Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-7631

Опубликовано: 19 мар. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can manipulate the path to retrieve any JSON files on the console's pod by using sequences of ../ and valid directory paths.

Отчет

Due to the affected endpoint's logic, only files with the .json extension can be accessed, greatly limiting the impact of this vulnerability. No JSON files with a potential security impact could be identified on the console's pod.

Меры по смягчению последствий

Red Hat Product Security does not have any recommended mitigations at this time. Please update to a patched version of the component as soon as it is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11openshift3/ose-consoleAffected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2296053openshift-console: OpenShift Console: Path traversal

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
10 месяцев назад

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can manipulate the path to retrieve any JSON files on the console's pod by using sequences of ../ and valid directory paths.

CVSS3: 4.3
github
10 месяцев назад

OpenShift Console Has a Path Traversal Vulnerability

EPSS

Процентиль: 33%
0.0013
Низкий

4.3 Medium

CVSS3