Vulnerability identifier: #VU92244
Vulnerability risk: Medium
CVSSv4.0: 1.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID:
CWE-ID:
CWE-200
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Red Hat OpenShift Container Platform
Client/Desktop applications /
Software for system administration
Vendor: Red Hat Inc.
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application within internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. A remote user controlling an account that has high enough permissions to obtain pod information from the openshift-image-registry namespace can use this obtained client secret to perform actions as the registry operator's Azure service account.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Red Hat OpenShift Container Platform: 4.15.0 - 4.15.17
External links
https://access.redhat.com/security/cve/CVE-2024-4369
https://bugzilla.redhat.com/show_bug.cgi?id=2278035
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.