← Back
Cloud / Container
CVE-2024-1139 high CVSS 7.7

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a re...

Summary

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

AI summary openai / gpt-4o

OCPのクラスター監視オペレーターで認証情報漏洩の脆弱性が発見されました。この脆弱性により、基本的なログイン情報を持ったリモートの攻撃者がポッドのマニフェストを確認し、リポジトリのプルシークレットを発見する可能性があります。脆弱性の詳細な対策が必要です。
❓ What is the problem
クラスター監視オペレーターにおける認証情報漏洩の脆弱性。
📍 Affected scope
OCPのクラスター監視オペレーター。
🔥 Severity
高い重要度。攻撃者は基本的なログイン情報を使い、機密情報にアクセス可能。
🔧 How to fix
Red Hatから提供されるセキュリティパッチを適用する。
🛡️ Workaround
権限のあるユーザーのみがログイン情報にアクセスできるように権限を制限する。
🔍 Detection
ポッドマニフェストのアクセス履歴を監査し、不正なアクセスを検出する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →