Impact
OpenChoreo’s cluster‑gateway exposed management APIs on an externally reachable agent listener without any authentication checks. This flaw allows an attacker who can reach the endpoint to invoke the /api/proxy/ and /api/exec/ routes, proxy requests to the Kubernetes API, and execute arbitrary commands inside pods in multi‑cluster environments. The resulting impact is full remote code execution on the target cluster with the privileges of the cluster‑gateway process, effectively compromising confidentiality, integrity, and availability of the entire Kubernetes data‑plane. The vulnerability is rated CVSS 9.6, reflecting its severe nature and the breadth of access it grants.
Affected Systems
All OpenChoreo installations prior to versions 1.0.2 and 1.1.2 are susceptible. The affected vendor is openchoreo and the product is the OpenChoreo platform.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. EPSS data is not available and it is not listed in the CISA KEV catalog. Because the vulnerable APIs are exposed behind an externally reachable listener, a remote attacker who can reach that endpoint can exploit it without authentication or other prerequisites. The likely attack vector is network access to the agent listener, which can lead to full command execution within pods and complete control over the Kubernetes data‑plane.
OpenCVE Enrichment