CVE-2024-5037

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_distributed_tracing:2.0:*:*:*:*:*:*:*

History

18 Jun 2024, 17:04

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2024-5037 - () https://access.redhat.com/security/cve/CVE-2024-5037 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2272339 - () https://bugzilla.redhat.com/show_bug.cgi?id=2272339 - Issue Tracking, Vendor Advisory
References () https://github.com/kubernetes/kubernetes/pull/123540 - () https://github.com/kubernetes/kubernetes/pull/123540 - Patch, Third Party Advisory
References () https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78 - () https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78 - Product
First Time Redhat openshift Distributed Tracing
Redhat openshift Container Platform
Redhat
CPE cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_distributed_tracing:2.0:*:*:*:*:*:*:*

06 Jun 2024, 14:17

Type Values Removed Values Added
Summary
  • (es) Se encontró una falla en Telemeter de OpenShift. Si se cumplen ciertas condiciones, un atacante puede usar un token falsificado para evitar la verificación del problema ("iss") durante la autenticación del token web JSON (JWT).

05 Jun 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-05 18:15

Updated : 2024-06-18 17:04


NVD link : CVE-2024-5037

Mitre link : CVE-2024-5037

CVE.ORG link : CVE-2024-5037


JSON object : View

Products Affected

redhat

  • openshift_distributed_tracing
  • openshift_container_platform
CWE
CWE-290

Authentication Bypass by Spoofing