Vulnerability Description
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does not verify the validity of the user's credentials. As a result, unauthenticated users can access this endpoint.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift Container Platform | 3.11 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2024-7079Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2299678Issue Tracking
- https://access.redhat.com/security/cve/CVE-2024-7079Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2299678Issue Tracking
FAQ
What is CVE-2024-7079?
CVE-2024-7079 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this en...
How severe is CVE-2024-7079?
CVE-2024-7079 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-7079?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openshift Container Platform.