6.8
CVE-2026-18382
- EPSS 0.27%
- Veröffentlicht 30.07.2026 12:00:29
- Zuletzt bearbeitet 12.08.2026 19:33:08
- CVE-Watchlists
- Unerledigt
Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Cost Management Metrics Operator Version- SwPlatformopenshift
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.189 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| RedHat | 6.8 | 2.3 | 4 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://access.redhat.com/security/cve/CVE-2026-18382
https://bugzilla.redhat.com/show_bug.cgi?id=2509253