Offcanvas

When Should We Call You?

Edit Template

Red Hat OpenShift Container Platform Vulnerability

Spread the love

Creation Date : March 21, 2025

Source : Red Hat Security Bulletin

Classification :

  • Impact: Loss of confidentiality
  • Exploit: Unknown exploit
  • Solution: Unknown solution

Product Status:

Vendor Product Version

Red Hat OpenShift 4

Conclusion

A vulnerability of medium severity has been identified in the OpenShift console at the /locales/resources.json endpoint, which is used to provide multilingual resources via plugins. The lng and ns parameters are insecurely handled in the code (pkg/plugins/handles/unsafely.go #L112) for generating file paths. This flaw allows an authenticated user to manipulate these parameters using sequences like ../ to access any JSON file on the console pod via a directory traversal attack.

References:

  • CVE-2024-7631
  • CVSS Score: 4.30
  • CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (Vector String)

Red Hat Bugzilla:

Vendor-Specific Advisory URL:

Mitigation:

  • Currently, Red Hat does not recommend mitigation measures. Please update to a patched version of the component as soon as it becomes available.

Spread the love

Leave a Reply

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *

Popular Articles

Most Recent Posts

  • All Post
  • Active Directory
  • azure
  • Azure Cloud
  • Azure Infrastructure
  • Azure Patch
  • Azure Security
  • Cloud
  • Cloud Computing
  • Exchange Server
  • Manage M365
  • Messaging
  • Microsoft
  • Microsoft 365
  • Microsoft Purview
  • News
  • Patch Tuesday
  • Request Call
  • Security
  • Security M365
  • Websites
  • Windows Server
  • Windows Server Patch

Information

Disclaimer

Privacy Statement

Terms of Service

ThankYou