Vulnerability Description
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Network Observability | 1.0 |
| Redhat | Enterprise Linux | 8.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2023:0786Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-0813Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2169468Issue TrackingVendor Advisory
- https://access.redhat.com/errata/RHSA-2023:0786Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-0813Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2169468Issue TrackingVendor Advisory
FAQ
What is CVE-2023-0813?
CVE-2023-0813 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who ...
How severe is CVE-2023-0813?
CVE-2023-0813 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-0813?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Network Observability, Redhat Enterprise Linux.