Impact
A flaw in the OpenShift console allows unauthenticated callers to POST to the /api/devfile and /api/devfile/samples endpoints. By sending crafted devfile payloads, an attacker can cause the console pod to perform arbitrary outbound HTTP requests, enabling Server‑Side Request Forgery that exposes internal services and partial responses. Repeated large payloads without a content‑length header lead to unbounded memory growth, potentially exhausting the console container’s resources and resulting in a denial of service.
Affected Systems
Affected product is Red Hat OpenShift Container Platform 4. The CVE does not provide specific version details, so it is unclear which releases are impacted; any installation that includes the OpenShift console could be vulnerable.
Risk and Exploitability
The CVSS score of 9.3 indicates a high‑severity flaw. The EPSS score of 0.00414 (less than 1%) indicates a very low but nonzero exploitation probability; combined with the lack of authentication and common HTTP endpoints the attack has a non‑negligible chance of success. The vulnerability is not listed in the CISA KEV catalog, meaning no publicly disclosed exploits are known. An attacker only needs network access to the cluster’s console pod, making the attack path straightforward. Exploitation proceeds by sending a crafted devfile payload via HTTP to the exposed endpoint, triggering either an internal SSRF or an unbounded memory allocation that brings the console pod down.
OpenCVE Enrichment