Vendor
high
advisory
Authorization Bypass in OpenChoreo API Endpoints
1 TTP 1 CVEAn authorization flaw in the OpenChoreo API server allows authenticated users with project-scoped grants to execute commands and access logs across different projects within the same namespace.
openchoreo-api +1
vulnerability
cloud-security
authorization-bypass
1t
1c
high
advisory
Authenticated OS Command Injection in OpenChoreo Workflow Plane
1 TTP 1 CVEAuthenticated users can trigger OS command injection in OpenChoreo workflow templates by supplying crafted parameters that are insecurely interpolated into shell execution scripts.
openchoreo
vulnerability
remote-code-execution
kubernetes
podman
1t
1c
critical
advisory
Unauthenticated API Access in OpenChoreo Cluster-Gateway
2 TTPs 1 CVEOpenChoreo cluster-gateway versions prior to 1.0.2, 1.1.2, and 1.2.0 are vulnerable to unauthenticated access of management APIs on externally exposed listeners, enabling remote execution and cluster-wide compromise.
OpenChoreo cluster-gateway
2t
1c