
Cloud Vulnerability DB
A community-led vulnerabilities database
A credentials leak vulnerability (CVE-2024-1139) was discovered in the cluster monitoring operator in OpenShift Container Platform (OCP). The vulnerability was first reported on January 31, 2024, and affects the telemeter-client pod running in the openshift-monitoring namespace. This security issue impacts OCP versions since 4.12 (Red Hat CVE, Bugzilla).
The vulnerability stems from an implementation flaw where the token string is concatenated with the hash instead of properly writing the token string to the hash object and calling Sum() with a nil slice. This occurs in the cluster-monitoring-operator's manifest handling code. The issue has been present since OCP 4.12 and affects the telemeter-client pod's configuration (Bugzilla).
The vulnerability allows any user with basic login credentials who can read the definition of the telemeter-client pod and/or deployment to gain access to the pull secret token for the cloud.openshift.com and quay.io registries. While users with cluster-reader clusterrole permissions already have access to the original pull secret through the 'pull-secret' Secret in the openshift-config namespace, this vulnerability potentially exposes sensitive credentials to users with more limited access (Bugzilla).
The vulnerability can be exploited by any authenticated user who has permissions to check pod manifests in the cluster. The attack vector requires basic login credentials and the ability to read pod definitions in the openshift-monitoring namespace (Red Hat CVE).
Red Hat has addressed this vulnerability through several security updates: RHSA-2024:1887 for OpenShift Container Platform 4.15, RHSA-2024:2047 for OpenShift Container Platform 4.13, and RHSA-2024:2782 for OpenShift Container Platform 4.12. Users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."