Redhat Service Interconnect vulnerabilities
3 known vulnerabilities affecting redhat/service_interconnect.
Total CVEs
3
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2024-6535MEDIUMCVSS 5.3v1.02024-07-17
CVE-2024-6535 [MEDIUM] CWE-1392 CVE-2024-6535: A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-a
A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an attacker to bypass authentication to the Skupper console via a specially-crafted cookie.
nvd
CVE-2023-5056MEDIUMCVSS 4.1v1.02023-12-18
CVE-2023-5056 [MEDIUM] CWE-862 CVE-2023-5056: A flaw was found in the Skupper operator, which may permit a certain configuration to create a servi
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.
nvd
CVE-2023-44487HIGHCVSS 7.5KEVPoCv1.02023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd