Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7079


A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does not verify the validity of the user's credentials. As a result, unauthenticated users can access this endpoint.


Published

2024-07-24T16:15:07.613

Last Modified

2024-11-21T09:50:50.600

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat openshift_container_platform 3.11 Yes
Application redhat openshift_container_platform 4.0 Yes

References