GHSA-x45c-cvp8-q4fm
HIGHCVE-2022-46167Capsule implements a multi-tenant and policy-based environment in a Kubernetes cluster. A ServiceAccount deployed in a Tenant Namespace, when granted with PATCH capabilities on its own Namespace, is able to edit it and remove the Owner Reference, breaking the reconciliation of the Capsule Operator and removing all the enforcement like Pod Security annotations, Network Policies, Limit Range and Res
- Affected
- >=0, <0.1.3
- Fixed in
- 0.1.3
- Published
- 2022-12-05
- Source
- github