CVE Published: 17/07/2024 |
CVE Updated: 24/11/2024 |
CVE Year: 2024 Source: redhat |
Vendor: Red Hat |
Product: Service Interconnect 1.4 for RHEL 9 Status : PUBLISHED
CVE-2024-6535 Description
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an attacker to bypass authentication to the Skupper console via a specially-crafted cookie.