PT-2024-38065 · Red Hat · Openshift Console

Michal Findra

+1

·

Published

2024-07-24

·

Updated

2024-09-19

·

CVE-2024-7079

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Openshift console (affected versions not specified)
Description A flaw was found in the Openshift console, specifically in the /API/helm/verify endpoint, which is responsible for fetching and verifying the installation of a Helm chart from a remote HTTP/HTTPS or local URI. The authHandlerWithUser() middleware function is supposed to gate access to this endpoint, but it does not verify the validity of the user's credentials, allowing unauthenticated users to access the endpoint.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-7079

Affected Products

Openshift Console