CVE-2024-1139
A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.89%
- CWE
- CWE-200
- Published
- 2024-04-25
- Last modified
- 2026-08-14
Affected products
- Red Hat Red Hat OpenShift Container Platform 4.12
- Red Hat Red Hat OpenShift Container Platform 4.13
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.14
- Red Hat Red Hat OpenShift Container Platform 4.14
Weakness type
Related vulnerabilities
- CVE-2026-92960 — vm2 before 3.11.6 Process-wide State Exposure via os and dns
- CVE-2026-92947 — vm2 before 3.11.7 Memory Disclosure via Buffer Pool
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity
- CVE-2026-67100 — HCL BigFix Service Management is affected by multiple security vulnerabilities.
- CVE-2026-54617 — GravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandler
- CVE-2026-87541 — Information leak in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the
- CVE-2026-78960 — Information leak in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin