Описание
A flaw was found in Fulcio's OpenID Connect (OIDC) Discovery client. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF) by redirecting discovery requests to internal systems. Additionally, an attacker can manipulate the JSON Web Key Set (JWKS) Uniform Resource Identifier (URI) to poison the verifier cache with malicious keys, enabling the validation of attacker-controlled signatures. Furthermore, the flaw can lead to the leakage of Kubernetes ServiceAccount tokens to third-party hosts through cross-host redirects or misconfigured MetaIssuers, potentially exposing sensitive cluster credentials.
Отчет
A flaw was found in Fulcio's OIDC Discovery client. Three related vulnerabilities allow exploitation when a configured OIDC issuer is compromised or malicious: (1) Blind SSRF — the discovery client follows cross-host HTTP redirects, allowing a malicious issuer to redirect Fulcio's metadata fetch requests to internal-only systems (e.g., cloud IMDS endpoints, RFC 1918 addresses); (2) JWKS substitution — the redirected discovery flow can return a manipulated jwks_uri pointing to an attacker-controlled host, poisoning the verifier cache with attacker keys and enabling validation of attacker-controlled signatures; (3) Kubernetes ServiceAccount token leakage — the in-cluster SA token is attached globally by the HTTP transport, leaking it to third-party hosts during cross-host redirects or when wildcard MetaIssuers match external endpoints. Exploitation requires a compromised or malicious OIDC issuer already trusted in the Fulcio configuration. In typical Red Hat Trusted Artifact Signer deployments, OIDC issuers are explicitly configured and curated, reducing the attack surface."}]
Меры по смягчению последствий
Upgrade to Fulcio v1.8.6 or later. No workaround is available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | assisted/agent-preinstall-image-builder-rhel9 | Affected | ||
| Assisted Installer for Red Hat OpenShift Container Platform 2 | fulcio | Not affected | ||
| Confidential Compute Attestation | fulcio | Not affected | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-must-gather-rhel9 | Affected | ||
| Kernel Module Management Operator for Red Hat Openshift | fulcio | Not affected | ||
| Kernel Module Management Operator for Red Hat Openshift | kmm/kernel-module-management-must-gather-rhel9 | Affected | ||
| Lightspeed Core | fulcio | Not affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Affected | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Affected | ||
| Logging Subsystem for Red Hat OpenShift | fulcio | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Fulcio has OIDC Discovery Redirect Following Allows SSRF and JWKS Substitution for Meta-Issuer Paths, with Kubernetes Service-Account Token Leakage
6.5 Medium
CVSS3