PT-2023-16542 · Grafana+1 · Loki+1

Michael Kaplan

·

Published

2023-09-15

·

Updated

2024-05-03

·

CVE-2023-0813

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift console (affected versions not specified)
Description A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2023-0813

Affected Products

Loki
Openshift Console