Database/Container, Kubernetes & orchestration
Contrast Coordinator: recovery accepts an unverified seed, enabling a rogue Coordinator to impersonate the real one
Impact
A recovering Contrast Coordinator does not verify the seed supplied by the recovering party, so an attacker can stand up a rogue Coordinator whose manifest validates but whose secret seed they control. If traffic is redirected from the real Coordinator to the rogue one, a workload owner who sets a new manifest without comparing the returned root CA against the existing one - the contrast CLI's default behaviour - or who verifies without checking the CA against a trusted reference, will be impersonated. The attacker can then issue certificates chaining to the rogue root CA and recover workload secrets for workloads deployed after the attack. For an operator this is a trust-anchor failure in the component that underwrites every confidential workload's identity; the legitimate Coordinator's own seed, CA and workload secrets, and certificates chaining to the mesh CA, are not affected. Versions before 1.4.1.
Who can reach it
Network position sufficient to redirect Coordinator traffic, plus a workload owner who proceeds without comparing the root CA - user interaction is part of the path. No prior authentication to the Coordinator is required.
What to do
Upgrade Contrast to 1.4.1 or later. Independently of the upgrade, pin and compare the Coordinator root CA against a trusted reference on every set-manifest and verify operation rather than trusting the CLI default. A control-plane component upgrade and redeploy; no node maintenance.
References
Related entries
- OpenShift Pipelines: every authenticated user gets write access to Kueue and cert-manager resourcesCVE-2026-10840 · Red Hat OpenShift Pipelines operator (tekton-scheduler-rolebinding ClusterRoleBinding)High
- Nuclio Dashboard: unsanitized build tempDir yields command execution in a pod holding namespace-wide Secrets accessCVE-2026-79754 · Nuclio Dashboard (spec.build.tempDir, Kaniko container builder)High
- Consul Connect: unescaped service names generate over-broad Envoy RBAC rules, bypassing intentionsCVE-2026-88021 · HashiCorp Consul Connect service mesh (Envoy RBAC rule generation)High
- Harbor: fuzzy q filter on scanner credentials lets a project admin extract the adapter secret character by characterCVE-2026-92770 · Harbor registry (scanner registration AccessCredential, q query parameter)High
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostCVE-2019-19921 · runcHigh
- Podman: File permissions not checked for non-root users in a privileged containerCVE-2021-20188 · PodmanHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.