VYPR

koku-metrics-operator

by Red Hat

CVEs (2)

  • CVE-2026-18381HigJul 30, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries…

  • CVE-2026-18378HigJul 30, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an arbitrary upload URL. When authentication.type is set to token (the default), the cluster-global Red Hat Cloud pull-secret bearer…