<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 15:43:52 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-158197</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-158197</link>
      <description>EUVD-2026-158197</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-158197</guid>
    </item>
    <item>
      <title>fkie_cve-2024-42480</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-42480</link>
      <description>&lt;p&gt;Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an &amp;#34;open at the top&amp;#34; range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Kamaji is the Hosted Control Plane Manager for Kubernetes. In versions 1.0.0 and earlier, Kamaji uses an &amp;#34;open at the top&amp;#34; range definition in RBAC for etcd roles leading to some TCPs API servers being able to read, write, and delete the data of other control planes. This vulnerability is fixed in edge-24.8.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-42480</guid>
    </item>
    <item>
      <title>GHSA-6r4j-4rjc-8vw5 — RBAC Roles for `etcd` created by Kamaji are not disjunct</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6r4j-4rjc-8vw5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/clastix/kamaji&lt;/p&gt;
&lt;p&gt;### Summary
_Using an &amp;#34;open at the top&amp;#34; range definition in RBAC for etcd roles leads to some TCPs API servers being able to read, write and delete the data of other control planes._&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The problematic code is this: https://github.com/clastix/kamaji/blob/8cdc6191242f80d120c46b166e2102d27568225a/internal/datastore/etcd.go#L19-L24&lt;/p&gt;
&lt;p&gt;The range created by this RBAC setup code looks like this:&lt;/p&gt;
&lt;p&gt;```
etcdctl role get example
Role example
KV Read:
	[/example/, \0)
KV Write:
	[/example/, \0)
```&lt;/p&gt;
&lt;p&gt;The range end `\0` means &amp;#34;everything that comes after&amp;#34; in etcd, so potentially all the key prefixes of controlplanes with a name that comes after &amp;#34;example&amp;#34; when sorting lexically (e.g. `example1`, `examplf`, all the way to `zzzzzzz` if you will).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Create two TCP in the same Namespace
2. Scale Kamaji to zero to avoid reconciliations
3. change the Kubernetes API Server `--etcd-prefix` flag value  to point to the other TCP datastore key
4. wait it for get it up and running
5. use `kubectl` and will notice you&amp;#39;re reading and writing data of another Tenant&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Full control over other TCPs data, if you are able to obtain the name of other TCPs that use the same datastore and are able to obtain the user certificates used by your control plane (or you are able to configure the kube-apiserver Deployment, as shown in the PoC).&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/clastix/kamaji&lt;/p&gt;
&lt;p&gt;### Summary
_Using an &amp;#34;open at the top&amp;#34; range definition in RBAC for etcd roles leads to some TCPs API servers being able to read, write and delete the data of other control planes._&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The problematic code is this: https://github.com/clastix/kamaji/blob/8cdc6191242f80d120c46b166e2102d27568225a/internal/datastore/etcd.go#L19-L24&lt;/p&gt;
&lt;p&gt;The range created by this RBAC setup code looks like this:&lt;/p&gt;
&lt;p&gt;```
etcdctl role get example
Role example
KV Read:
	[/example/, \0)
KV Write:
	[/example/, \0)
```&lt;/p&gt;
&lt;p&gt;The range end `\0` means &amp;#34;everything that comes after&amp;#34; in etcd, so potentially all the key prefixes of controlplanes with a name that comes after &amp;#34;example&amp;#34; when sorting lexically (e.g. `example1`, `examplf`, all the way to `zzzzzzz` if you will).&lt;/p&gt;
&lt;p&gt;### PoC&lt;/p&gt;
&lt;p&gt;1. Create two TCP in the same Namespace
2. Scale Kamaji to zero to avoid reconciliations
3. change the Kubernetes API Server `--etcd-prefix` flag value  to point to the other TCP datastore key
4. wait it for get it up and running
5. use `kubectl` and will notice you&amp;#39;re reading and writing data of another Tenant&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Full control over other TCPs data, if you are able to obtain the name of other TCPs that use the same datastore and are able to obtain the user certificates used by your control plane (or you are able to configure the kube-apiserver Deployment, as shown in the PoC).&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6r4j-4rjc-8vw5</guid>
    </item>
  </channel>
</rss>
