An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with only view permission. In this short time window the user with view permission could read cluster secrets that should only be disclosed to admin users.
| Software | From | Fixed in |
|---|---|---|
| redhat / advanced_cluster_management_for_kubernetes | 2.0 | 2.0.x |