CVE-2024-6538

MEDIUM

OpenShift Console - Authenticated Server-Side Request Forgery via /api/dev-console/proxy/internet Endpoint

Title source: llm
STIX 2.1

Description

A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed services that aren't readily available to clients due to network filtering. Leveraging such an attack vector, the attacker can have an impact on other services and potentially disclose information or have other nefarious effects on the system. The /api/dev-console/proxy/internet endpoint on the OpenShift Console allows authenticated users to have the console's pod perform arbitrary and fully controlled HTTP(s) requests. The full response to these requests is returned by the endpoint. While the name of this endpoint suggests the requests are only bound to the internet, no such checks are in place. An authenticated user can therefore ask the console to perform arbitrary HTTP requests from outside the cluster to a service inside the cluster.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:14397
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:19058
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:7863
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:8280
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:8556
Vendor Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2024-6538
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2296057

Scores

CVSS v3 5.3
EPSS 0.0017
EPSS Percentile 38.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (6)
openshift/console 0Go
Red Hat/Red Hat OpenShift Container Platform 4.14 sha256:5593067bbf79e50ab9ed89c684c8ee03b4b2a0b6443068459967df623c0643de
Red Hat/Red Hat OpenShift Container Platform 4.15 sha256:8d6e2390929560bdddddf8caab133f14fa50dbd53a5e551f134680837778e180
Red Hat/Red Hat OpenShift Container Platform 4.16 v4.16.0-202506020836.p0.g94ae640.assembly.stream.el9
Red Hat/Red Hat OpenShift Container Platform 4.17 v4.17.0-202505280435.p0.gf9c412e.assembly.stream.el9
Red Hat/Red Hat OpenShift Container Platform 4.18 v4.18.0-202505150334.p0.g75bc164.assembly.stream.el9
Published Nov 25, 2024
Tracked Since Feb 18, 2026