CVE-2024-7631

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Mar 19, 2025
CWE ID 22

Summary

CVE-2024-7631 is a vulnerability affecting the OpenShift Console's endpoint for plugins, specifically the /locales/resources.json route. The issue lies in the unsafely constructed filepath in the pkg/plugins/handlers unsafely.go file at line 112. Due to this unsafe construction, an authenticated user can manipulate the path using sequences of ../ and valid directory paths to access any JSON files on the console's pod. This could potentially lead to sensitive information disclosure or unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share