CVE-2023-32194

Severity CVSS v4.0:
HIGH
Type:
CWE-269 Improper Privilege Management
Publication date:
16/10/2024
Last modified:
16/10/2024

Description

A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive *<br /> permissions for core namespaces. This can lead to someone being capable<br /> of accessing, creating, updating, or deleting a namespace in the <br /> project.