{"id":"CVE-2024-6535","aliases":["GO-2024-2987"],"url":"https://o3.security/vulnerability/CVE-2024-6535","summary":"Skupper uses a static cookie secret for the openshift oauth-proxy","details":"A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift oauth-proxy with a static cookie-secret. In certain circumstances, this may allow an attacker to bypass authentication to the Skupper console via a specially-crafted cookie.","published":"2024-07-17T03:31:38Z","modified":"2024-11-18T16:26:52Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/skupperproject/skupper","fixedVersion":"0.0.0-20240703184342-c26bce4079ff"}],"fix":{"url":"https://github.com/skupperproject/skupper/commit/d2cb3782e807853694ee66b6e3d4a1917485eb71","label":"skupperproject/skupper@d2cb378"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6535"},{"type":"WEB","url":"https://github.com/skupperproject/skupper/commit/d2cb3782e807853694ee66b6e3d4a1917485eb71"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4865"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:4871"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-6535"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2296024"},{"type":"PACKAGE","url":"https://github.com/skupperproject/skupper"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-18T16:26:52Z"}}