Unprotected Transport of Credentials in Go SDK for CloudEvents - CVE-2024-28110
Published: April 3, 2024
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exist due to an error in the cloudevents.WithRoundTripper method used for creation of a cloudevents.Client with an authenticated http.RoundTripper. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. As a result, a remote attacker can intercept credentials leaked by the go-sdk.
Affected software
Red Hat OpenShift Serverless
Red Hat OpenShift Container Platform
How to mitigate CVE-2024-28110
Red Hat OpenShift Serverless - update to 1.32.0
Red Hat OpenShift Container Platform - addressed in versions 4.15.37, 4.16.0
External References
Related Security Bulletins
- Credentials disclosure in Go SDK for CloudEvents
- Multiple vulnerabilities in Red Hat OpenShift Serverless
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.16
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15