First published: Fri Mar 21 2025(Updated: )
The OpenShift Lightspeed Service does not enforce authentication when logging metrics for API requests, including those made to non-existent endpoints. This allows unauthenticated users to send a large volume of requests to arbitrary, non-existent endpoints, causing excessive metric entries. As a result, this behavior can lead to high CPU and memory usage, degraded application performance, and potential denial of service conditions for monitoring and logging components.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Lightspeed Service |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2353998 is considered to be high due to its potential for denial of service.
To fix REDHAT-BUG-2353998, ensure proper authentication mechanisms are implemented for logging metrics in the OpenShift Lightspeed Service.
REDHAT-BUG-2353998 can lead to excessive metric entries and possible denial of service from unauthenticated request floods.
Users of the Red Hat OpenShift Lightspeed Service are affected by REDHAT-BUG-2353998.
Exploitation of REDHAT-BUG-2353998 may result in system performance degradation due to high volumes of unnecessary metrics being recorded.