The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsThere is no fixed version for github.com/openshift/cluster-image-registry-operator
.
github.com/openshift/cluster-image-registry-operator is a The registry operator manages a singleton instance of the openshift registry. It manages all configuration of the registry including creating storage.
Affected versions of this package are vulnerable to Information Exposure Through Environmental Variables due to the exposure of AZURE_CLIENT_SECRET
through an environment variable defined in the pod definition, limited to Azure environments. An attacker controlling an account with sufficient permissions to obtain pod information from the openshift-image-registry
namespace could use this obtained client secret to perform actions as the registry operator's Azure service account.
Note
This is only exploitable if the attacker has high enough permissions to access pod information within the specified namespace.