VYPR

insights-client

by Red Hat

CVEs (5)

  • CVE-2026-71846MedAug 12, 2026
    risk 0.42cvss 6.5epss

    A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the…

  • CVE-2026-71845MedAug 11, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in…

  • CVE-2026-71474MedAug 11, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This…

  • CVE-2026-71475MedAug 11, 2026
    risk 0.33cvss 5.0epss 0.00

    A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper…

  • CVE-2023-3972HigNov 1, 2023
    risk 0.00cvss 7.8epss 0.00

    A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an…