REDHAT-BUG-2233087: Medium severity openshift vulnerability

Published Aug 21, 2023
·
Updated

The opa-openshift component is responsible for authorizing the requests going to the LokiStack through the gateway. Requests are authenticated using a token and authorization happens by, among other things, checking for an RBAC privilege. To reduce the number of SubjectAccessReviews the result of the authorization is cached in opa-openshift for a while. Currently, the key used for this caching is just the token, which is too broad and allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

Affected Software

1 affected component
Openshift opa-openshift

Event History

Aug 21, 2023
Data Sourced
via Red Hat·11:43 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2233087?

The severity of REDHAT-BUG-2233087 is categorized as critical.

2

How do I fix REDHAT-BUG-2233087?

To fix REDHAT-BUG-2233087, update to the latest patched version of the opa-openshift component.

3

What software is affected by REDHAT-BUG-2233087?

The affected software includes the OpenShift opa-openshift component.

4

What issue does REDHAT-BUG-2233087 address?

REDHAT-BUG-2233087 addresses problems related to authorization and RBAC privilege checks in the opa-openshift component.

5

When was REDHAT-BUG-2233087 reported?

REDHAT-BUG-2233087 was reported in 2023.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203