CyberRota Analysis
AI-GeneratedA path traversal vulnerability in the OpenShift console allows unauthenticated attackers to manipulate the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint, potentially exposing sensitive JSON files from the pod filesystem, such as plugin manifests and configuration files. This high-severity flaw could lead to unauthorized access to critical information, making it essential for organizations using OpenShift to prioritize immediate remediation efforts. Security teams should focus on patching this vulnerability to protect against potential data breaches and exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.