A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the OpenShift Console in an OpenShift cluster to retrieve flows without authentication.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2023-09-15T20:17:41.914Z

Updated: 2024-05-03T15:32:31.244Z

Reserved: 2023-02-13T16:49:21.409Z


Link: CVE-2023-0813

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-09-15T21:15:08.953

Modified: 2024-05-03T16:15:09.690


Link: CVE-2023-0813

JSON object: View

cve-icon Redhat Information

No data.