CVE-2024-5037
Estado: ModificadaAlta (7.5)—
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.81%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-290
Referencias
- https://access.redhat.com/errata/RHSA-2024:4151
- https://access.redhat.com/errata/RHSA-2024:4156
- https://access.redhat.com/errata/RHSA-2024:4329
- https://access.redhat.com/errata/RHSA-2024:4484
- https://access.redhat.com/errata/RHSA-2024:5200
- https://access.redhat.com/security/cve/CVE-2024-5037
- https://bugzilla.redhat.com/show_bug.cgi?id=2272339
- https://github.com/kubernetes/kubernetes/pull/123540
- https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78
- https://access.redhat.com/errata/RHSA-2024:4151
- https://access.redhat.com/errata/RHSA-2024:4156
- https://access.redhat.com/errata/RHSA-2024:4329
- https://access.redhat.com/errata/RHSA-2024:4484
- https://access.redhat.com/security/cve/CVE-2024-5037
- https://bugzilla.redhat.com/show_bug.cgi?id=2272339
- https://github.com/kubernetes/kubernetes/pull/123540
- https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-5037",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-5037",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-13T20:15:59.404791Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "4.16",
"lessThan": "4.17",
"versionType": "semver"
}
],
"packageName": "telemeter",
"collectionURL": "https://github.com/openshift/telemeter",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.12::el8",
"cpe:/a:redhat:openshift:4.12::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.12",
"versions": [
{
"status": "unaffected",
"version": "v4.12.0-202408071159.p0.gc9592de.assembly.stream.el8",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "openshift4/ose-telemeter",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.13::el8",
"cpe:/a:redhat:openshift:4.13::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.13",
"versions": [
{
"status": "unaffected",
"version": "v4.13.0-202407081338.p0.g0634a6d.assembly.stream.el8",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "openshift4/ose-telemeter",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.14::el8",
"cpe:/a:redhat:openshift:4.14::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.14",
"versions": [
{
"status": "unaffected",
"version": "v4.14.0-202407021509.p0.g1f72681.assembly.stream.el8",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "openshift4/ose-telemeter",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.15::el8",
"cpe:/a:redhat:openshift:4.15::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.15",
"versions": [
{
"status": "unaffected",
"version": "v4.15.0-202406200537.p0.g14489f7.assembly.stream.el9",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "openshift4/ose-telemeter-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.16::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.16",
"versions": [
{
"status": "unaffected",
"version": "v4.16.0-202406200537.p0.gc1ecd10.assembly.stream.el9",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "openshift4/ose-telemeter-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:logging:5"
],
"vendor": "Red Hat",
"product": "Logging Subsystem for Red Hat OpenShift",
"packageName": "openshift-logging/opa-openshift-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:2"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 2",
"packageName": "rhosdt/tempo-gateway-opa-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3",
"packageName": "rhosdt/tempo-gateway-opa-rhel8",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2024-06-05T18:15:11.747",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2024:4151",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4156",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4329",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4484",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:5200",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2024-5037",
"tags": [
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272339",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/kubernetes/kubernetes/pull/123540",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78",
"tags": [
"Product"
],
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4151",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4156",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4329",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2024:4484",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2024-5037",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272339",
"tags": [
"Issue Tracking",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/kubernetes/kubernetes/pull/123540",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/openshift/telemeter/blob/a9417a6062c3a31ed78c06ea3a0613a52f2029b2/pkg/authorize/jwt/client_authorizer.go#L78",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-290"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue (\"iss\") check during JSON web token (JWT) authentication."
},
{
"lang": "es",
"value": "Se encontró una falla en Telemeter de OpenShift. Si se cumplen ciertas condiciones, un atacante puede usar un token falsificado para evitar la verificación del problema (\"iss\") durante la autenticación del token web JSON (JWT)."
}
],
"lastModified": "2026-06-17T08:14:57.353",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "932D137F-528B-4526-9A89-CD59FA1AB0FE"
},
{
"criteria": "cpe:2.3:a:redhat:openshift_distributed_tracing:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC859D38-CE10-4898-96CF-681BC3714AF7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}