PT-2026-46191 · Red Hat+2 · Openshift Pipelines+2
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
OpenShift Pipelines operator (affected versions not specified)
Description
A flaw in the OpenShift Pipelines operator occurs because the
tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources through the tekton-scheduler-role ClusterRole. If Kueue or cert-manager Custom Resource Definitions (CRDs) are present on the cluster, any authenticated user can disrupt workload scheduling, tamper with scheduling priorities, delete Workload objects belonging to other tenants, or cause cert-manager to overwrite TLS Secrets, including the default ingress controller certificate.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kueue
Openshift Pipelines
Cert-Manager