PT-2024-38095 · Red Hat · Openshift Console

Michal Findra

+1

·

Published

2024-07-26

·

Updated

2025-08-13

·

CVE-2024-7128

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenShift console (affected versions not specified)
Description A flaw was found in the OpenShift console, where several endpoints use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider is set to "openShiftAuth", these functions do not perform authentication checks, relying on the targeted service for authentication and authorization. This leads to data exposure due to a lack of proper credential verification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-7128

Affected Products

Openshift Console