#VU92244 Information disclosure in Red Hat OpenShift Container Platform


Published: 2024-06-19

Vulnerability identifier: #VU92244

Vulnerability risk: Medium

CVSSv3.1: 5.6 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-4369

CWE-ID: CWE-200

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Red Hat OpenShift Container Platform
Client/Desktop applications / Software for system administration

Vendor: Red Hat Inc.

Description

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application within internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. A remote user controlling an account that has high enough permissions to obtain pod information from the openshift-image-registry namespace can use this obtained client secret to perform actions as the registry operator's Azure service account.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

Red Hat OpenShift Container Platform: 4.15.0 - 4.15.17


External links
http://access.redhat.com/security/cve/CVE-2024-4369
http://bugzilla.redhat.com/show_bug.cgi?id=2278035


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability