PT-2024-38065 · Red Hat · Openshift Console
Michal Findra
+1
·
Published
2024-07-24
·
Updated
2024-09-19
·
CVE-2024-7079
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Openshift console (affected versions not specified)
Description
A flaw was found in the Openshift console, specifically in the
/API/helm/verify endpoint, which is responsible for fetching and verifying the installation of a Helm chart from a remote HTTP/HTTPS or local URI. The authHandlerWithUser() middleware function is supposed to gate access to this endpoint, but it does not verify the validity of the user's credentials, allowing unauthenticated users to access the endpoint.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Console