CVE-2026-18382
- EPSS 0.27%
- Veröffentlicht 30.07.2026 12:00:29
- Zuletzt bearbeitet 12.08.2026 19:33:08
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sen...
CVE-2026-18378
- EPSS 0.23%
- Veröffentlicht 30.07.2026 12:00:27
- Zuletzt bearbeitet 17.08.2026 13:51:56
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red H...
CVE-2026-18381
- EPSS 0.19%
- Veröffentlicht 30.07.2026 12:00:05
- Zuletzt bearbeitet 12.08.2026 19:27:29
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-acc...