An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be able to migrate a malicious workload to the target cluster, impacting confidentiality, integrity, and availability of the services located on that cluster.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "1.5.2"
},
{
"introduced": "1.6.0"
},
{
"fixed": "1.6.3"
}
],
"cpes": [
"cpe:2.3:a:konveyor:mig-controller:*:*:*:*:*:*:*:*"
],
"vendor_product": "konveyor:mig-controller",
"source": "CPE_RANGE"
},
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:redhat:migration_toolkit:1.5:*:*:*:*:containers:*:*",
"cpe:2.3:a:redhat:migration_toolkit:1.6:*:*:*:*:containers:*:*"
],
"vendor_product": "redhat:migration_toolkit",
"extracted_events": [
{
"introduced": "1.5"
},
{
"last_affected": "1.5"
},
{
"introduced": "1.6"
},
{
"last_affected": "1.6"
}
]
}
]
}