CVE-2024-7631

A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can manipulate the path to retrieve any JSON files on the console's pod by using sequences of ../ and valid directory paths.
Configurations

No configuration.

History

19 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-19 19:15

Updated : 2025-03-19 19:15


NVD link : CVE-2024-7631

Mitre link : CVE-2024-7631

CVE.ORG link : CVE-2024-7631


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')