#VU94763 Improper Authentication in Service Interconnect - CVE-2024-6535
Published: July 26, 2024
Service Interconnect
Red Hat Inc.
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. A remote attacker can bypass authentication process using a specially crafted cookie file and gain unauthorized access to the application.