Impact
An authenticated Server Side Request Forgery (SSRF) flaw exists in the OpenShift Console Dev Console webhook helpers. The console allows a user to supply arbitrary target URLs, which are fetched server‑side without validation and with path neutralization. The console pod, running in a privileged network position, can therefore reach and ultimately reflect the full response from any internal or external endpoint specified by the attacker, potentially exposing sensitive data or allowing further internal actions.
Affected Systems
All Red Hat OpenShift Container Platform 4 instances are affected. The vulnerability is tied to the console component of OpenShift, which runs in the openshift-console namespace. Since no specific patch versions are listed, any deployment of the OpenShift 4 Console with this feature is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity flaw that necessitates prompt mitigation. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, but its nature allows authenticated users to make arbitrary requests to any internal service and have the console’s responses directly reflected back, enabling discovery of internal network topology or sensitive data. Exploitation requires legitimate console access, so the threat is bounded to authenticated users, but once accessed it can reach a wide range of internal endpoints.
OpenCVE Enrichment