Description
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 30 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat cost Management Metrics Operator |
|
| Vendors & Products |
Red Hat
Red Hat cost Management Metrics Operator |
Thu, 30 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token. | |
| Title | Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address | |
| First Time appeared |
Redhat
Redhat cost Management |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:/a:redhat:cost_management:4 | |
| Vendors & Products |
Redhat
Redhat cost Management |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-30T12:14:46.389Z
Reserved: 2026-07-30T11:37:06.496Z
Link: CVE-2026-18381
Updated: 2026-07-30T12:14:34.231Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T13:59:46Z
Weaknesses
-
CWE-918
Server-Side Request Forgery (SSRF)