CVE-2024-7631

Executive Summary

CVE-2024-7631 exposes a path‑traversal flaw in OpenShift Console’s /locales/resources.json endpoint. Unsafely constructed file paths from the lng and ns query parameters allow authenticated users to traverse directories (using ../) and read arbitrary JSON files on the console pod, potentially leaking sensitive configuration or code. The vulnerability requires authentication but grants broad read access to the pod’s filesystem.


Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2025-03-19T19:15:43.920 - Last Modified: 2026-09-03T16:17:21.820

Original Description: A flaw was found in the OpenShift Console, an endpoint for plugins to serve resources in multiple languages: /locales/resources.json. This endpoint's lng and ns parameters are used to construct a filepath in pkg/plugins/handlers unsafely.go#L112 Because of this unsafe filepath construction, an authenticated user can manipulate the path to retrieve any JSON files on the console's pod by using sequences of ../ and valid directory paths.

"Meaning is not what you start with but what you end up with."

— Peter Elbow
Source: NVD