The Submariner project received a security disclosure regarding unnecessary RBAC that could be used to spread K8s node compromises. If an attacker is able to run a privileged malicious container on a node, they may be able to escape the container and steal service account tokens. Since Submariner's route agent runs on every node, its SA token is available from any compromised node. References: https://github.com/submariner-io/submariner-operator/issues/3041
This issue has been addressed in the following products: RHODF-4.16-RHEL-9 Via RHSA-2024:4591 https://access.redhat.com/errata/RHSA-2024:4591