PT-2023-16542 · Grafana+1 · Loki+1
Michael Kaplan
·
Publicado
2023-09-15
·
Atualizado
2024-05-03
·
CVE-2023-0813
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift console (affected versions not specified)
Description
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki
authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Loki
Openshift Console