REDHAT-BUG-2517886: High severity Openshift OpenShift Console vulnerability
The CatalogdHandler() in the OpenShift console is registered without authHandler (pkg/server/server.go:340). Furthermore, the CatalogdProxyConfig is the only proxy config that omits HeaderBlacklist: srv.ProxyHeaderDenyList (cmd/bridge/main.go:429-432), so the user's openshift-session-token cookie is forwarded verbatim to the catalogd service.
Any unauthenticated network actor can GET /api/catalogd/<arbitrary-path> and the console pod will issue a TLS request to catalogd-service.openshift-catalogd.svc:443/<arbitrary-path>. This discloses the full operator-catalog index (intended to be cluster-internal) and provides a relay primitive into the openshift-catalogd namespace.
Tested and reproduced on OCP 5.0 nightly cluster.
Upstream: https://github.com/openshift/console File: pkg/server/server.go:340, pkg/server/server.go:859-868, cmd/bridge/main.go:429-432
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An unauthenticated network actor can send a GET request to /api/catalogd/<arbitrary-path>. No authentication is enforced by the affected CatalogdHandler().
What can an attacker access through the vulnerable endpoint?
The console pod makes a TLS request to catalogd-service.openshift-catalogd.svc:443 using the supplied path. This can disclose the full operator-catalog index and provide a relay into the openshift-catalogd namespace.
Are session cookies exposed to the catalogd service?
Yes. The CatalogdProxyConfig omits the proxy header deny list, so the user's openshift-session-token cookie is forwarded verbatim to catalogd.