Security Bypass Vulnerability in Red Hat OpenShift oauth-proxy
A vulnerability in the Red Hat OpenShift oauth-proxy component, identified as CVE-2024-5254, allows a remote authenticated attacker to bypass security controls and manipulate data.
CVE search metadata
CVE search record: CVE-2024-5254. Severity: medium. CVSS: 6.4. EPSS: 0.30%. KEV: no. Product: OpenShift Container Platform. Brief: Security Bypass Vulnerability in Red Hat OpenShift oauth-proxy. Brief link: https://feed.craftedsignal.io/briefs/2026-08-openshift-oauth-proxy-bypass/
Red Hat has identified a security vulnerability affecting the oauth-proxy component within the OpenShift Container Platform, tracked as CVE-2024-5254. This flaw allows a remote, authenticated attacker to bypass established security restrictions. The vulnerability stems from improper handling of specific request patterns during the authentication and authorization flow. An attacker successful in exploiting this vulnerability can manipulate data or perform unauthorized operations within the affected OpenShift environment. Because the proxy is a critical component for managing access to containerized services, this flaw poses a risk to the integrity of service deployments and the underlying data accessed through the OpenShift API. Defenders should prioritize patching affected OpenShift clusters to mitigate the risk of unauthorized access and potential data manipulation by authenticated entities within the environment.
Impact
Successful exploitation of this vulnerability permits an authenticated attacker to perform actions that should be restricted by the oauth-proxy, leading to potential unauthorized data modification or administrative actions within the cluster. This affects organizations relying on OpenShift for secure container orchestration and service access control.
Recommendation
- Apply the security update provided by Red Hat for the OpenShift Container Platform to remediate CVE-2024-5254 across all cluster environments.
- Review OpenShift audit logs for unexpected or anomalous HTTP requests targeting the oauth-proxy endpoint, particularly those utilizing atypical URL path patterns.
- Verify authorization policies are correctly enforced for sensitive services behind the proxy following the application of the vendor-supplied patch.
Immediate actions
Patch OpenShift Container Platform to the version containing the fix for CVE-2024-5254.
Mitigations
Update OpenShift Container Platform to patched release.
CVE-2024-5254