Description
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-12818 | A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication. |
References
History
Wed, 25 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-09-25T13:35:54.194Z
Reserved: 2023-02-13T16:49:21.409Z
Link: CVE-2023-0813
Updated: 2024-08-02T05:24:34.543Z
Status : Modified
Published: 2023-09-15T21:15:08.953
Modified: 2024-11-21T07:37:53.203
Link: CVE-2023-0813
OpenCVE Enrichment
No data.
EUVD