Fedora Account System
Red Hat Associate
Red Hat Customer
GetImagePath returns imageOverrides[component] verbatim with zero validation — no registry allow-list, no digest requirement, no signature check. The resulting image runs with Privileged: true, Capabilities: ALL, hostNetwork, RW hostPath mounts, on every node (route-agent) including control-plane nodes. A cluster-admin or anyone who can patch the Submariner CR can point any component to a malicious image and achieve privileged code execution across the entire cluster. Source: Project Glasswing AI-SAST audit of submariner-io/submariner-operator. Finding ID: FIND-006 Assurance: machine_verified