Описание
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
A flaw was found in Kibana where the CrowdStrike connector stores credentials in a way that allows them to be accessed from other spaces. A malicious user could create and run a CrowdStrike connector in a space they control to access cached credentials belonging to another space, leading to unauthorized data access or manipulation.
Отчет
The impact is MODERATE because the exploitation requires a Kibana user with access to at least one space to trigger the attack. However, once exploited, the flaw exposes stored CrowdStrike API credentials that could be used to query or modify protected resources. The issue is fundamentally caused by insufficient credential isolation between spaces in the CrowdStrike connector.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrike connector in another space by creating and running a Crowdstrike connector in a space to which they have access.
EPSS
5.4 Medium
CVSS3