CVE-2024-7631
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Mar 19, 2025
CWE ID 22
Summary
CVE-2024-7631 is a vulnerability affecting the OpenShift Console's endpoint for plugins, specifically the /locales/resources.json route. The issue lies in the unsafely constructed filepath in the pkg/plugins/handlers unsafely.go file at line 112. Due to this unsafe construction, an authenticated user can manipulate the path using sequences of ../ and valid directory paths to access any JSON files on the console's pod. This could potentially lead to sensitive information disclosure or unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.