VYPR

Cluster Monitoring Operator

by Openshift

Source repositories

CVEs (2)

  • CVE-2026-10609modJun 23, 2026
    risk 0.44cvss 6.8epss

    openshift/cluster-logging-operator: Cluster Logging Operator creates and forwards ServiceAccount tokens without verifying CLF creator authorization

  • CVE-2024-1139HigApr 25, 2024
    risk 0.43cvss 7.7epss 0.01

    A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.