Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1139

Опубликовано: 03 апр. 2024
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rbac-query-proxy-containerNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/endpoint-monitoring-rhel8-operatorNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grafana-dashboard-loader-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/metrics-collector-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/multicluster-observability-rhel8-operatorNot affected
Red Hat OpenShift Container Platform 3.11openshift3/ose-cluster-monitoring-operatorOut of support scope
Red Hat OpenShift Container Platform 4.12openshift4/ose-cluster-monitoring-operatorFixedRHSA-2024:278216.05.2024
Red Hat OpenShift Container Platform 4.13openshift4/ose-cluster-monitoring-operatorFixedRHSA-2024:204702.05.2024
Red Hat OpenShift Container Platform 4.14openshift4/cloud-network-config-controller-rhel8FixedRHSA-2024:189126.04.2024
Red Hat OpenShift Container Platform 4.14openshift4/driver-toolkit-rhel9FixedRHSA-2024:189126.04.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2262158cluster-monitoring-operator: credentials leak

EPSS

Процентиль: 43%
0.00206
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
почти 2 года назад

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

CVSS3: 7.7
github
почти 2 года назад

Withdrawn Advisory: Cluster Monitoring Operator contains a credentials leak

EPSS

Процентиль: 43%
0.00206
Низкий

7.7 High

CVSS3