CVE-2024-7079
The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local.
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does not verify the validity of the user's credentials. As a result, unauthenticated users can access this endpoint.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.36% probability · 30th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-306
- Affected
- redhat/openshift container platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2024-7079Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2299678Issue Tracking
- https://access.redhat.com/security/cve/CVE-2024-7079Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2299678Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.