The vendor explicitly identifies these products as affected by this CVE.
- edo/external-dns-rhel8 as a component of ExternalDNS Operator
- edo/external-dns-rhel9 as a component of ExternalDNS Operator
- openshift4/ose-contour-rhel8 as a component of Red Hat OpenShift Container Platform 4
- Summary
- A flaw was found in Contour. When an HTTPProxy is configured with both a fallback certificate and JWT (JSON Web Token) providers, Contour does not properly enforce JWT verification. This allows remote attackers to bypass security checks by sending requests without a valid token, specifically when clients do not provide a TLS Server Name Indication (SNI) or provide an unrecognized SNI. The consequence is unauthorized access to upstream services and potential information disclosure.
- Remediation
- Upgrade to Contour v1.33.5 or later. As a workaround, do not enable enableFallbackCertificate on HTTPProxy resources that also define jwtProviders.
