Описание
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Logging Subsystem for Red Hat OpenShift | openshift-logging/opa-openshift-rhel8 | Not affected | ||
Red Hat OpenShift distributed tracing 2 | rhosdt/tempo-gateway-opa-rhel8 | Affected | ||
Red Hat OpenShift distributed tracing 3 | rhosdt/tempo-gateway-opa-rhel8 | Affected | ||
Red Hat OpenShift Container Platform 4.12 | openshift4/ose-telemeter | Fixed | RHSA-2024:5200 | 19.08.2024 |
Red Hat OpenShift Container Platform 4.13 | openshift4/ose-telemeter | Fixed | RHSA-2024:4484 | 17.07.2024 |
Red Hat OpenShift Container Platform 4.14 | openshift4/ose-telemeter | Fixed | RHSA-2024:4329 | 11.07.2024 |
Red Hat OpenShift Container Platform 4.15 | openshift4/ose-telemeter-rhel9 | Fixed | RHSA-2024:4151 | 02.07.2024 |
Red Hat OpenShift Container Platform 4.16 | openshift4/ose-telemeter-rhel9 | Fixed | RHSA-2024:4156 | 03.07.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
Уязвимость программного средства для сбора информации о состоянии и производительности приложений, работающих на платформе OpenShift, OpenShift Telemeter, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
7.5 High
CVSS3