Impact
A Server‑Side Request Forgery flaw exists in the OpenShift Console’s Helm catalog proxy. By creating a ProjectHelmChartRepository in a tenant namespace with an arbitrary URL, a tenant can cause the console pod to fetch that resource server‑side, thereby bypassing the tenant’s egress restrictions. The same flaw also permits catalog metadata poisoning, and when combined with an admin‑mediated chart installation, it can elevate the tenant’s privileges to administrative level.
Affected Systems
The vulnerability affects Red Hat OpenShift Container Platform 4 installations. Any cluster that exposes the console service and allows tenants to create ProjectHelmChartRepository resources is vulnerable, irrespective of the base OS or operator layer.
Risk and Exploitability
The CVSS score of 7.4 indicates moderate‑to‑high severity. Because the exploit relies on the tenant’s ability to create a ProjectHelmChartRepository, it can be performed from within a tenant’s namespace without any external network access. The lack of an EPSS value does not negate the potential for exploitation; the flaw remains fully leveraged by an attacker with namespace access. The vulnerability’s absence from the CISA KEV catalog suggests no known public attacks yet, but the combination of SSRF, supply‑chain poisoning, and privilege escalation makes it a compelling candidate for immediate mitigation.
OpenCVE Enrichment