CVE-2026-71474
EUVD-2026-5690211.08.2026, 20:18
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized access to Red Hat cloud services.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | advanced_cluster_management_for_kubernetes | 2.0 |
| redhat | insights-client | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References