A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2023-08-21T15:19:22.208Z

Updated: 2024-09-16T12:51:53.422Z

Reserved: 2023-08-21T11:46:25.407Z

Link: CVE-2023-4456

cve-icon Vulnrichment

Updated: 2024-08-02T07:31:05.461Z

cve-icon NVD

Status : Modified

Published: 2023-08-21T17:15:50.283

Modified: 2023-11-07T04:22:38.447

Link: CVE-2023-4456

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-08-21T00:00:00Z

Links: CVE-2023-4456 - Bugzilla