CyberRota Analysis
AI-GeneratedA vulnerability exists in the OpenShift Console Helm catalog proxy, allowing a namespace tenant to inject a ProjectHelmChartRepository with an arbitrary URL, which the console pod fetches server-side, circumventing egress restrictions. This flaw, combined with catalog metadata manipulation and admin-mediated chart installations, can lead to privilege escalation within the system. Organizations using OpenShift should prioritize addressing this vulnerability to mitigate potential security risks.
Original NVD Description
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation.