VDB
BDU%3A2024-04494
BDU%3A2024-04494
PUBLISHED
CVSS 7.5 HIGH
Уязвимость программного средства для сбора информации о состоянии и производительности приложений, работающих на платформе OpenShift, OpenShift Telemeter, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.16 | v4.16.0-202406200537.p0.gc1ecd10.assembly.stream.el9 |
| Red Hat | Red Hat OpenShift Container Platform 4.14 | v4.14.0-202407021509.p0.g1f72681.assembly.stream.el8 |
| Red Hat | Red Hat OpenShift Container Platform 4.15 | v4.15.0-202406200537.p0.g14489f7.assembly.stream.el9 |
| Red Hat | Red Hat OpenShift Container Platform 4.13 | v4.13.0-202407081338.p0.g0634a6d.assembly.stream.el8 |
| Red Hat | Logging Subsystem for Red Hat OpenShift | |
| Red Hat | Red Hat OpenShift Container Platform 4.12 | v4.12.0-202408071159.p0.gc9592de.assembly.stream.el8 |
| Red Hat Inc., Google Inc | Red Hat OpenShift Container Platform, Red Hat OpenShift distributed tracing, Kubernetes | |
| Red Hat | Red Hat OpenShift distributed tracing 2 | |
| Red Hat | Red Hat OpenShift distributed tracing 3 | |
| 4.16 |
Timeline
- Jun 5, 2024 CVE Published
- Jun 13, 2024 CVE Updated
- Aug 30, 2026 Distribution Patch
- Aug 30, 2026 Security Advisory
- Aug 30, 2026 Distribution Patch
- Aug 30, 2026 Distribution Patch
- Aug 30, 2026 Distribution Patch
- Aug 30, 2026 Distribution Patch
- Aug 30, 2026 Security Advisory
- Aug 30, 2026 Security Advisory
- Aug 30, 2026 Security Advisory
- Aug 30, 2026 Security Advisory
References
- RHSA-2024:5200 vendor-advisory
- RHSA-2024:4151 vendor-advisory
- RHSA-2024:4156 vendor-advisory
- RHSA-2024:4329 vendor-advisory
- RHSA-2024:4484 vendor-advisory
- RHBZ#2272339 issue
- https://access.redhat.com/security/cve/CVE-2024-5037 advisory
- https://github.com/golang/vulndb/issues/2905 url
- https://github.com/advisories/GHSA-gc8r-pxj9-hhx3 url
- https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78 url
- https://github.com/kubernetes/kubernetes/pull/123540 url
- https://github.com/kubernetes/kubernetes/commit/236f1b0f6b4cbb7e372a72d181c6285bdaf74873 url
- https://github.com/openshift/telemeter/commit/fa7aa6c36e12e894dc883a9a48591fa1700c9a7f url
- https://security.snyk.io/vuln/SNYK-GOLANG-K8SIOKUBERNETESPKGSERVICEACCOUNT-7216074 url