CVE-2024-5037

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.

Production-Grade Container Scheduling and Management
GitHubGitHub
123K
Prometheus push federation
GitHubGitHub
106