Information disclosure in Red Hat OpenShift Container Platform - CVE-2022-2403
Published: July 25, 2022
Red Hat OpenShift Container Platform
Red Hat Inc.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the private key for the external cluster certificate is stored incorrectly in the oauth-serving-cert ConfigMaps and accessible to any authenticated OpenShift user or service-account. A remote user can read the oauth-serving-cert ConfigMap in the openshift-config-managed namespace and compromise any web traffic secured using that certificate.