multicluster-global-hub
by Red Hat
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-71576 | Hig | 0.55 | 8.5 | 0.00 | Aug 10, 2026 | A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the… | ||
| CVE-2026-75762 | imp | 0.44 | 6.8 | — | Aug 31, 2026 | multicluster-global-hub: multicluster-global-hub: Transport-layer MITM: TLS CA bundle pulled from unvalidated ConfigMap, `InsecureSkipVerify` fallback | ||
| CVE-2026-71577 | Med | 0.41 | 6.3 | 0.00 | Aug 10, 2026 | A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which… |
- risk 0.55cvss 8.5epss 0.00
A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status topics. A remote attacker, after compromising a managed hub and obtaining its Kafka client certificate, can manipulate the…
- risk 0.44cvss 6.8epss —
multicluster-global-hub: multicluster-global-hub: Transport-layer MITM: TLS CA bundle pulled from unvalidated ConfigMap, `InsecureSkipVerify` fallback
- risk 0.41cvss 6.3epss 0.00
A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sensitive bootstrap kubeconfigs, which…