CyberRota Analysis
AI-GeneratedA vulnerability exists in the koku-metrics-operator, where the CostManagementMetricsConfig custom resource allows users to specify an arbitrary upload URL. This flaw can lead to the exposure of the cluster-global Red Hat Cloud pull-secret bearer token in HTTP requests, enabling attackers to gain unauthorized access to sensitive resources. Organizations using this operator, especially those with default token authentication, should prioritize remediation to mitigate the risk of credential theft.
Original NVD Description
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer token is attached to HTTP requests sent to this user-controlled URL, allowing the attacker to obtain the token.
Related CVEs
Other vulnerabilities affecting the same vendor(s)