PT-2026-70152 · Red Hat · Openshift Console
CVE-2026-50237
·
Published
2026-08-11
·
Updated
2026-08-31
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
OpenShift Console (affected versions not specified)
Description
A Server-Side Request Forgery (SSRF) and supply chain flaw exists in the OpenShift Console Helm catalog proxy. A namespace tenant can create a
ProjectHelmChartRepository using an arbitrary URL, which the console pod then fetches server-side. This action allows the bypass of tenant egress restrictions. When combined with catalog metadata poisoning and chart installation performed by an administrator, this flaw can lead to privilege escalation.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Console