CVE-2024-5037 - CVE House
Back to Database
Status published High CVE-2024-5037

Openshift/telemeter: iss check during jwt authentication can be bypassed

Vulnerability Description

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5037

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Red Hat OpenShift Container Platform 4.12, Red Hat OpenShift Container Platform 4.13, Red Hat OpenShift Container Platform 4.14, Red Hat OpenShift Container Platform 4.15, Red Hat OpenShift Container Platform 4.16, Logging Subsystem for Red Hat OpenShift, Red Hat OpenShift distributed tracing 2, Red Hat OpenShift distributed tracing 3
Vulnerable Versions:
4.16, v4.12.0-202408071159.p0.gc9592de.assembly.stream.el8, v4.13.0-202407081338.p0.g0634a6d.assembly.stream.el8, v4.14.0-202407021509.p0.g1f72681.assembly.stream.el8, v4.15.0-202406200537.p0.g14489f7.assembly.stream.el9, v4.16.0-202406200537.p0.gc1ecd10.assembly.stream.el9

Timeline

Official Publish: June 5th, 2024
Last Modified: April 30th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)