-
Bug
-
Resolution: Unresolved
-
Major
-
None
-
4.14, 4.15, 4.16, 4.17, 4.18
-
None
-
False
-
-
N/A
-
Release Note Not Required
-
Done
This is a clone of issue OCPBUGS-44056. The following is the description of the original issue:
—
https://github.com/openshift/machine-api-provider-azure/tree/main/pkg/cloud/azure/services/virtualnetworks
This package is not used within MAPI, but its presence indicates that the operator needs permissions over VNets, specifically to delete VNets. This is a sensitive permission that if exercised could lead to an unrecoverable cluster, or deletion of other critical infrastructure within the same Azure subscription or resource group that's not related to the cluster itself. This package should be removed as well as the relevant permissions from the CredentialsRequest.
- blocks
-
OCPBUGS-52476 MAPI operator for Azure has overly permissive actions over VNets
-
- ASSIGNED
-
- clones
-
OCPBUGS-44056 MAPI operator for Azure has overly permissive actions over VNets
-
- Closed
-
- is blocked by
-
OCPBUGS-44056 MAPI operator for Azure has overly permissive actions over VNets
-
- Closed
-
- is cloned by
-
OCPBUGS-52476 MAPI operator for Azure has overly permissive actions over VNets
-
- ASSIGNED
-
- links to
-
RHSA-2025:2445 OpenShift Container Platform 4.17.z security update