Redhat

Insights-client

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.12%
  • Veröffentlicht 12.08.2026 21:46:19
  • Zuletzt bearbeitet 05.09.2026 18:17:28

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege me...

  • EPSS 0.2%
  • Veröffentlicht 11.08.2026 19:24:56
  • Zuletzt bearbeitet 05.09.2026 18:17:28

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-live...

  • EPSS 0.28%
  • Veröffentlicht 11.08.2026 19:24:18
  • Zuletzt bearbeitet 05.09.2026 18:17:28

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the reque...

  • EPSS 0.21%
  • Veröffentlicht 11.08.2026 19:22:12
  • Zuletzt bearbeitet 05.09.2026 18:17:28

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or high...

  • EPSS 0.27%
  • Veröffentlicht 01.11.2023 16:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:25

A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered...