NA

CVE-2023-4456

Published: 21/08/2023 Updated: 07/11/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift logging

Vendor Advisories

Description<!---->A flaw was found in openshift-logging LokiStack The key used for caching is just the token, which is too broad This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cachedA flaw was found in openshift-logging LokiStack The key used ...