odf4/odf-multicluster-rhel9-operator vulnerabilities
CVEs whose affected-version data names the odf4/odf-multicluster-rhel9-operator package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-66792Critical· 9.9A flaw was found in the multicloud-operators-subscription component
A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitatio…
▾ MidnightRed Hat · multicluster-globalhub/multicluster-globalhub-agent-rhel9EPSS 0.43%via NVD
CVE-2024-5042Medium· 6.6A flaw was found in the Submariner project
A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromis…
▾ SunlitRed Hat · submariner-operatorEPSS 0.50%via NVD