CVE-2022-46167
vulnerability analysis and mitigation

Overview

CVE-2022-46167 is a high-severity vulnerability discovered in github.com/clastix/capsule affecting versions 0.1.2 and earlier, disclosed on December 2, 2022. The vulnerability exists in the Capsule Operator's namespace management functionality, where a ServiceAccount deployed in a Tenant Namespace could potentially break out of its security constraints (GitHub Advisory).

Technical details

The vulnerability occurs when a ServiceAccount in a Tenant Namespace is granted PATCH capabilities on its own Namespace. The technical issue allows the ServiceAccount to edit and remove the Owner Reference from the namespace, which breaks the Capsule Operator's reconciliation process. This circumvents critical security enforcements including Pod Security annotations, Network Policies, Limit Range, and Resource Quota items (GitHub Advisory).

Impact

The impact of this vulnerability is significant as it allows an attacker to detach the Namespace from a Tenant that is forbidding privileged Pod execution using Pod Security labels. By removing the OwnerReference and enforcement labels, an attacker could start privileged containers, potentially leading to a broader Kubernetes privilege escalation scenario (GitHub Advisory, FortiGuard).

Mitigation and workarounds

The vulnerability has been patched in version 0.1.3 of the Capsule Operator. All users are strongly advised to upgrade to this version as there are no alternative workarounds available. The fix includes additional security checks to prevent ServiceAccounts from modifying critical namespace metadata (GitHub Release).

Community reactions

The release of version 0.1.3 was marked as critical by the project maintainers, emphasizing the severity of the security issue. The fix was implemented promptly and included in a release that also contained various other enhancements and improvements to the project (GitHub Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management