Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x5m7-63c6-fx79

Опубликовано: 25 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.7

Описание

Withdrawn Advisory: Cluster Monitoring Operator contains a credentials leak

Withdrawn Advisory

This advisory has been withdrawn because the vulnerability does not affect a package in the Go registry. For more information, see the discussion here. This link is maintained to preserve external references.

Original Description

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

Пакеты

Наименование

github.com/openshift/cluster-monitoring-operator

go
Затронутые версииВерсия исправления

<= 0.1.1

Отсутствует

EPSS

Процентиль: 43%
0.00206
Низкий

7.7 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.7
redhat
почти 2 года назад

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

CVSS3: 7.7
nvd
почти 2 года назад

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

EPSS

Процентиль: 43%
0.00206
Низкий

7.7 High

CVSS3

Дефекты

CWE-200