Back

HIGH

Skupper: potential authentication bypass to skupper console via forged cookies

Published Jul 17, 2024

Description

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an attacker to bypass authentication to the Skupper console via a specially-crafted cookie.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 17, 2024
Updated Nov 20, 2025
Reserved Jul 5, 2024
CISA Vulnrichment
Updated Jul 17, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 17, 2024
ENISA EUVD
Assigner redhat
Published Jul 17, 2024
Updated Nov 20, 2025
Exploited since n/a
EUVD-2024-2433 GHSA-W799-V85J-88PG