Vulnerabilidad · Publicado 08/09/2026
Se identificó una falla en hawtio-operator que permite al operador acceder a todos los Secretos del cluster mediante permisos excesivos en ClusterRole (create, get, list, update, watch). El compromiso del pod del operador exponendría credenciales y tokens en todos los namespaces, afectando la seguridad de infraestructuras Kubernetes en producción en México y LATAM. El riesgo es alta (CVSS 8.2) para empresas que despliegan este operador en plataformas cloud o on-premises.
A flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets.
Score: 8.2/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
CWE-269
Publicado en NIST NVD.