CVE-2024-13484

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.
Configurations

No configuration.

History

12 Feb 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en ArgoCD. La etiqueta openshift.io/cluster-monitoring se aplica a todos los espacios de nombres que implementan una instancia CR de ArgoCD, lo que permite que el espacio de nombres cree una PrometheusRule no autorizada. Este problema puede tener efectos adversos en la pila de monitoreo de la plataforma, ya que la regla se implementa en todo el clúster cuando se aplica la etiqueta.
Summary (en) A flaw was found in ArgoCD. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied. (en) A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can have adverse effects on the platform monitoring stack, as the rule is rolled out cluster-wide when the label is applied.

28 Jan 2025, 19:15

Type Values Removed Values Added
CWE CWE-668

28 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-28 18:15

Updated : 2025-02-12 17:15


NVD link : CVE-2024-13484

Mitre link : CVE-2024-13484

CVE.ORG link : CVE-2024-13484


JSON object : View

Products Affected

No product.

CWE
CWE-668

Exposure of Resource to Wrong Sphere