Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). The GitOpsCluster controller uses the tenant-controlled spec.argoServer.argoNamespace field to determine where spoke cluster bearer token Secrets are written. The controller copies ManagedServiceAccount tokens from privileged managed-cluster hub namespaces into the attacker-specified namespace. The only guard (VerifyArgocdNamespace) is bypassed by a tenant-settable annotation on the same CR. A tenant can exfiltrate spoke bearer tokens and bypass ArgoCD AppProject constraints. Upstream repo: https://github.com/stolostron/multicloud-integrations Audited commit: d88a168 Jira tracker: ACM-38644