GHSA-99j8-wv67-4c72
MODERATECVE-2026-39961A developer with create permission on ClickhouseUser CRDs in their own namespace can exfiltrate secrets from any other namespace — production database credentials, API keys, service tokens — with a single kubectl apply. The operator reads the victim's secret using its ClusterRole and writes the password into a new secret in the attacker's namespace.
- Affected
- >=0.31.0, <0.37.0, >= 0.31.0, < 0.37.0
- Fixed in
- 0.37.0
- Weakness
- CWE-269
- Published
- 2026-04-10
- Source
- osv