← Retour
CVE-2024-1139
high
CVSS 7.7
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a re...
Résumé
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2024-1139** a été découverte dans credential-leak.
Des informations confidentielles peuvent être exposées. Score CVSS : 7.7/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « credential-leak CVE-2024-1139 » sur le site de l'éditeur.
CVE-2024-1139 (credential-leak) — CWE-200 / CVSS v3 7.7
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
クラスター監視オペレーターにおける認証情報漏洩の脆弱性。
📍 Périmètre concerné
OCPのクラスター監視オペレーター。
🔥 Gravité
高い重要度。攻撃者は基本的なログイン情報を使い、機密情報にアクセス可能。
🔧 Comment corriger
Red Hatから提供されるセキュリティパッチを適用する。
🛡️ Contournement
権限のあるユーザーのみがログイン情報にアクセスできるように権限を制限する。
🔍 Détection
ポッドマニフェストのアクセス履歴を監査し、不正なアクセスを検出する。