https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4456
Source: CVEAnnouncements
Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4456
A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached. https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4456 Source: CVEAnnouncements Source Link: https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4456
|
|