Bug 2512152 (CVE-2026-71473) - CVE-2026-71473 acm-search-v2-rhel9: CVE-2026-71473 search-v2-operator: addonfactory.GetValuesFromAddonAnnotation enables arbitrary Helm-values override per spoke
Summary: CVE-2026-71473 acm-search-v2-rhel9: CVE-2026-71473 search-v2-operator: addonf...
Keywords:
Status: NEW
Alias: CVE-2026-71473
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 19:35 UTC by OSIDB Bzimport
Modified: 2026-08-12 20:45 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 19:35:57 UTC
addon-framework's GetValuesFromAddonAnnotation reads the addon.open-cluster-management.io/values annotation on a ManagedClusterAddOn and deep-merges arbitrary JSON into the Helm values. Because it is listed after getValue, it can override global.imageOverrides.search_collector, org, fullnameOverride, etc. A user with patch managedclusteraddons permission in a single managed-cluster namespace can replace the collector image for that spoke without touching the hub Search CR, achieving container image injection on the managed cluster.

Upstream: stolostron/search-v2-operator


Note You need to log in before you can comment on or make changes to this bug.