PT-2023-16542 · Grafana+1 · Loki+1
Michael Kaplan
·
Published
2023-09-15
·
Updated
2024-05-03
·
CVE-2023-0813
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift console (affected versions not specified)
Description
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki
authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Loki
Openshift Console