important · Edge — OpenShift
Unauthenticated OpenShift console requests can proxy into cluster-internal services.
Affects
Red Hat OpenShift Container Platform console, the web management interface deployed with OpenShift Kubernetes clusters.
A caller reaching the public devfile endpoints can make the console pod request an attacker-selected internal URL and receive part of its response.
Detail and 2 sources
The same parser can exhaust console memory with requests lacking a declared content length, and the accessible record does not identify exact fixed builds.