Database/Container, Kubernetes & orchestration
Strimzi: generated Role grants Kafka Connect and MirrorMaker 2 GET on all Secrets in the namespace
Impact
In some configurations Strimzi creates an incorrect Kubernetes Role that gives the Kafka Connect and MirrorMaker 2 operands GET access to every Secret in their namespace, not just the ones they need. Anyone who can run code in those pods - through a connector plugin, a Connect REST-configured task, or a compromised image - can read unrelated Secrets sharing the namespace, which in a data-pipeline namespace typically means object-store keys, registry pull secrets and downstream service credentials. On a shared cluster this is a lateral-movement primitive: the credential blast radius of a single Connect pod becomes the whole namespace. Affects 0.47.0 up to but not including 0.49.1.
Who can reach it
Requires the ability to execute within a Kafka Connect or MirrorMaker 2 pod, or to influence what it runs (for example connector plugin submission). Not exploitable from outside the cluster without that foothold.
What to do
Upgrade the Strimzi operator to 0.49.1 or later and let it reconcile, then confirm the regenerated Roles no longer carry cluster-wide Secret GET in the namespace. Where reconciliation does not narrow an existing Role, correct it manually. Operator upgrade and operand rollout only - no node maintenance.
References
Related entries
- BentoML (bentofile.yaml path fields: description, docker.setup_script, docker.dockerfile_templateCVE-2026-24123 · BentoMLHigh
- OpenShift Console: tenant-planted Helm repository makes the console pod fetch arbitrary URLs server-sideCVE-2026-50237 · Red Hat OpenShift Console (Helm catalog proxy, ProjectHelmChartRepository)High
- Envoy Gateway: unauthenticated xDS on port 18000 hands out TLS private keys and full routing configCVE-2026-53714 · Envoy Gateway xDS gRPC server in GatewayNamespaceMode (port 18000)High
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsCVE-2020-8595 · IstioHigh
- containerd: Overly broad default permissions on containerd-managed directoriesCVE-2024-25621 · containerdHigh
- runc: Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables containerCVE-2025-31133 · runcHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.