{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/cost-management-metrics-operator/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cost Management Metrics Operator"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eThe koku-metrics-operator is vulnerable to a Server-Side Request Forgery (SSRF) flaw, identified as CVE-2026-18378. The vulnerability exists within the CostManagementMetricsConfig custom resource, which lacks sufficient input validation when defining an upload URL for metrics. An attacker with privileges to edit this custom resource can define an attacker-controlled endpoint as the destination for metric uploads. When the authentication.type is set to the default 'token' configuration, the operator automatically attaches the cluster-global Red Hat Cloud pull-secret bearer token to outgoing HTTP requests. This results in the leakage of sensitive cluster credentials to an external server controlled by the attacker. This issue impacts the Red Hat Cost Management Metrics Operator and is classified as a high-severity credential access vector.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains administrative access to the Kubernetes cluster or specific namespace permissions allowing modification of custom resources.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves or identifies the existing koku-metrics-operator deployment in the cluster.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the CostManagementMetricsConfig custom resource.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a malicious, attacker-controlled URL into the configuration field intended for metric uploads.\u003c/li\u003e\n\u003cli\u003eOperator service attempts to transmit metrics to the attacker-supplied URL using the configured token authentication.\u003c/li\u003e\n\u003cli\u003eThe outgoing HTTP request includes the cluster-global Red Hat pull-secret bearer token in the Authorization header.\u003c/li\u003e\n\u003cli\u003eAttacker receives and captures the bearer token from the incoming request logs on their controlled server.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes the stolen bearer token to potentially access Red Hat Cloud services or perform unauthorized actions within the authenticated scope of the token.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to steal the cluster-global pull-secret. This credential provides the ability to authenticate as the cluster to Red Hat services, potentially leading to unauthorized data access, service manipulation, or further credential compromise across the associated cloud environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit existing CostManagementMetricsConfig resources for unauthorized or unexpected destination URLs.\u003c/li\u003e\n\u003cli\u003eMonitor Kubernetes audit logs for modifications to the koku-metrics-operator custom resource definitions.\u003c/li\u003e\n\u003cli\u003eApply available patches from Red Hat for the affected operator once released.\u003c/li\u003e\n\u003cli\u003eRestrict RBAC permissions for modifying CostManagementMetricsConfig to the minimum necessary users to prevent unauthorized configuration changes.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-30T13:40:50Z","date_published":"2026-07-30T13:40:50Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-18378/","summary":"An SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.","title":"Credential Exfiltration via koku-metrics-operator SSRF","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-18378/"}],"language":"en","title":"CraftedSignal Threat Feed - Cost Management Metrics Operator","version":"https://jsonfeed.org/version/1.1"}