← Zurück zur CVE-Suche

CVE-2026-71475

Beschreibung

A flaw was found in insights-client. A compromised managed cluster, referred to as a -spoke-, can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability allows a malicious spoke to redirect authenticated requests to unintended API endpoints, potentially leading to information disclosure or unauthorized access.

CVSS 5EPSS 0%Risiko 0.5
Quelle öffnen
Veröffentlicht
2026-08-11 20:18:45
Zuletzt geändert
2026-08-11 20:18:45
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N