Description
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54312 | A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached. |
References
History
Sat, 30 Aug 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-20T18:27:42.202Z
Reserved: 2023-08-21T11:46:25.407Z
Link: CVE-2023-4456
Updated: 2024-08-02T07:31:05.461Z
Status : Modified
Published: 2023-08-21T17:15:50.283
Modified: 2024-11-21T08:35:12.040
Link: CVE-2023-4456
OpenCVE Enrichment
No data.
Weaknesses
EUVD