REDHAT-BUG-2333540: High severity Skupper Skupper Console vulnerability
When a skupper site is initialized with the console enabled and the default authentication method selected, it configures the skupper console with a flawed basic auth implementation. This implementation can be manipulated by an actor with network access to bypass authentication or to DOS the skupper console - potentially impacting the functionality of the skupper installation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2333540?
The severity of REDHAT-BUG-2333540 is critical due to the potential for unauthorized access and denial of service.
How do I fix REDHAT-BUG-2333540?
To fix REDHAT-BUG-2333540, disable the console or use a secure authentication mechanism until a patch is applied.
What systems are affected by REDHAT-BUG-2333540?
REDHAT-BUG-2333540 affects the Skupper Console when initialized with the console enabled and default authentication.
What kind of attack does REDHAT-BUG-2333540 expose systems to?
REDHAT-BUG-2333540 exposes systems to potential bypass of authentication and denial of service attacks.
Is a patch available for REDHAT-BUG-2333540?
Currently, a patch for REDHAT-BUG-2333540 is not mentioned, so immediate mitigation steps are recommended.