CVE-2024-4369

May 1, 2024, 1:02 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

OpenShift

Source

secalert@redhat.com

Tags

CVE-2024-4369 details

Published : May 1, 2024, 12:15 a.m.
Last Modified : May 1, 2024, 1:02 p.m.

Description

An information disclosure flaw was found in OpenShift's internal image registry operator. AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. An attacker controlling an account that has high enough permissions to obtain pod information from the openshift-image-registry namespace could use this obtained client secret to perform actions as the registry operator's Azure service account.

CVSS Score

1 2 3 4 5 6.8 7 8 9 10

Weakness

Weakness Name Description

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

Base Score

6.8

Exploitability Score

Impact Score

Base Severity

MEDIUM

This website uses the NVD API, but is not approved or certified by it.