← Back
CVE-2024-1139
high
CVSS 7.7
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a re...
Summary
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
AI summary openai / gpt-4o
OCPのクラスター監視オペレーターで認証情報漏洩の脆弱性が発見されました。この脆弱性により、基本的なログイン情報を持ったリモートの攻撃者がポッドのマニフェストを確認し、リポジトリのプルシークレットを発見する可能性があります。脆弱性の詳細な対策が必要です。
❓ What is the problem
クラスター監視オペレーターにおける認証情報漏洩の脆弱性。
📍 Affected scope
OCPのクラスター監視オペレーター。
🔥 Severity
高い重要度。攻撃者は基本的なログイン情報を使い、機密情報にアクセス可能。
🔧 How to fix
Red Hatから提供されるセキュリティパッチを適用する。
🛡️ Workaround
権限のあるユーザーのみがログイン情報にアクセスできるように権限を制限する。
🔍 Detection
ポッドマニフェストのアクセス履歴を監査し、不正なアクセスを検出する。