CVE-2024-7079

CVSS V2 None CVSS V3 None
Description
A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does not verify the validity of the user's credentials. As a result, unauthenticated users can access this endpoint.
Overview
  • CVE ID
  • CVE-2024-7079
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-07-24T15:51:36.331Z
  • Last Modified Date
  • 2024-07-24T18:09:33.310Z
References
Reference URL Reference Tags
https://access.redhat.com/security/cve/CVE-2024-7079 vdb-entry x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=2299678 issue-tracking x_refsource_REDHAT
History
Created Old Value New Value Data Type Notes
2024-07-25 13:03:57 Added to TrackCVE