PT-2024-9926 · Unknown · Skupper Console

Published

2024-12-20

·

Updated

2026-05-06

·

CVE-2024-12582

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Skupper console (affected versions not specified)
Description: A flaw was found in the Skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a user sets up across a hybrid multi-cloud environment. When the default authentication method is used, a random password is generated for the "admin" user and is persisted in either a Kubernetes secret or a podman volume in a plaintext file. This authentication method can be manipulated by an attacker, leading to the reading of any user-readable file in the container filesystem, directly impacting data confidentiality. Additionally, the attacker may induce Skupper to read extremely large files into memory, resulting in resource exhaustion and a denial of service attack.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

BDU:2025-00037
CVE-2024-12582

Affected Products

Skupper Console