Fedora Account System
Red Hat Associate
Red Hat Customer
There is no validation that advertised IPs in EndpointSlice objects fall within the source cluster's allocated Pod/Service/Globalnet CIDR, nor that they are not link-local, loopback, or the importing cluster's own control-plane addresses. A compromised spoke can create an EndpointSlice with attacker-controlled IP addresses for any service name, causing peer clusters' lighthouse DNS to resolve legitimate service names to malicious endpoints. This enables transparent MITM of cross-cluster service traffic without modifying the target service. Source: Project Glasswing AI-SAST audit of submariner-io/lighthouse. Finding ID: FIND-001 Assurance: execution_proven