2022/01/24
Bored-agent failed to sanitize incoming kubernetes impersonation headers allowing a user to override assigned user name and groups.
Bored-agent prior to v0.6.1
CVE-2022-0270
8.8 (HIGH) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-284
Upgrade to v0.6.1 or later. In most installations, this should be automatic.
None
Found by Mirantis PSIRT
2022/01/24: public advisory released
2022/01/18: fixed in lensapp/bored-agent#144
2022/01/18: Mirantis PSIRT reported vulnerability to Lens team