CVE-2024-22032
Severity CVSS v4.0:
HIGH
Type:
CWE-200
Information Leak / Disclosure
Publication date:
16/10/2024
Last modified:
16/10/2024
Description
A vulnerability has been identified in which an RKE1 cluster keeps <br />
constantly reconciling when secrets encryption configuration is enabled.<br />
When reconciling, the Kube API secret values are written in plaintext <br />
on the AppliedSpec. Cluster owners, Cluster members, and Project members<br />
(for projects within the cluster), all have RBAC permissions to view <br />
the cluster object from the apiserver.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM



