CVE-2024-6535
17.07.2024, 03:15
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an attacker to bypass authentication to the Skupper console via a specially-crafted cookie.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | service_interconnect | 1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-1392 - Use of Default CredentialsThe product uses default credentials (such as passwords or cryptographic keys) for potentially critical functionality.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References