CyberRota Analysis
AI-GeneratedA critical vulnerability in the OpenShift console allows unauthenticated remote attackers to access the `/api/devfile/` and `/api/devfile/samples/` endpoints, potentially leading to Server-Side Request Forgery (SSRF) and Denial of Service (DoS) through unbounded memory growth. Organizations using OpenShift should prioritize patching this flaw to prevent unauthorized access to internal services and mitigate the risk of service disruption. Immediate action is essential for any entity relying on OpenShift for their operations.
Original NVD Description
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to internal services and reflects partial responses to the attacker. Additionally, by sending repeated large requests without a specified content length, an attacker can cause unbounded memory growth, leading to a Denial of Service (DoS).