Impact
The vulnerability allows an attacker who can edit the CostManagementMetricsConfig custom resource to specify an arbitrary upload URL. When the operator’s authentication.type is set to token (the default), the Bearer token in the cluster‑global Red Hat Cloud pull‑secret is automatically attached to HTTP requests sent to that user‑controlled URL, letting the attacker retrieve the privileged token.
Affected Systems
Red Hat Cost Management Metrics Operator, version 4.
Risk and Exploitability
With a CVSS score of 7.6 the flaw is considered high‑severity. The exploitation requires privileges to modify the custom resource, which may be limited by RBAC but is still a realistic risk in environments where users have such access. The EPSS score is < 1%, indicating a low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through an authorized edit of the CR that points to an external endpoint, where the operator will send the token as part of the request header. The resultant token exposure could enable broad compromise of cloud resources.
OpenCVE Enrichment