A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider ("openShiftAuth") is set, these functions do not perform any authentication checks, relying instead on the targeted service to handle authentication and authorization. This issue leads to various degrees of data exposure due to a lack of proper credential verification.
Metrics
Affected Vendors & Products
References
History
Wed, 13 Aug 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.16::el9 | |
| References |
|
Thu, 15 May 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.17::el9 | |
| References |
|
Fri, 09 May 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:openshift:4.18::el9 | |
| References |
|
Tue, 03 Dec 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: redhat
Published: 2024-07-26T13:34:19.647Z
Updated: 2025-08-13T09:02:41.359Z
Reserved: 2024-07-26T10:55:18.431Z
Link: CVE-2024-7128
Updated: 2024-08-01T21:52:30.646Z
Status : Awaiting Analysis
Published: 2024-07-26T14:15:03.573
Modified: 2025-08-13T09:15:26.920
Link: CVE-2024-7128