Impact
The vulnerability lies in the CostManagementMetricsConfig custom resource used by the Cost Management Metrics Operator. An attacker who can edit this resource can specify an arbitrary OAuth token endpoint. When the operator is configured to use a service‑account for authentication, it sends the tenant’s Red Hat SSO client ID and client secret to the user‑controlled URL, exposing those credentials. The exposed client credentials enable the attacker to impersonate the tenant and perform privileged actions within the tenant’s environment. The weakness is a type of information‑exposure flaw (CWE‑918).
Affected Systems
This issue affects Red Hat Cost Management Metrics Operator, version 4 of the product.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. The EPSS score is less than 1%, implying a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have permission to modify the CostManagementMetricsConfig custom resource, typically an administrator or a privileged cluster user. Once the CR is altered, the operator automatically transmits the client credentials to the attacker‑controlled endpoint without further user interaction, making the attack path simple for an authenticated privileged user.
OpenCVE Enrichment