Vulnerabilities (CVE)

Filtered by vendor Redhat Subscribe
Filtered by product Cost Management Metrics Operator
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-18382 1 Redhat 1 Cost Management Metrics Operator 2026-08-12 N/A 6.8 MEDIUM
A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO client_id and client_secret to this user-controlled URL, allowing the attacker to obtain the credentials.
CVE-2026-18381 1 Redhat 1 Cost Management Metrics Operator 2026-08-12 N/A 7.6 HIGH
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries sent to this user-controlled URL, allowing the attacker to obtain the token.