Vendor
high
advisory
Authentication Bypass and Credential Exposure in OpenCost
1 rule 2 TTPs 1 CVEOpenCost versions before 1.121.0 contain authentication bypass vulnerabilities allowing unauthenticated credential exfiltration via GET /helmValues and unauthorized service key modification via POST /serviceKey.
OpenCost
1r
2t
1c
high
advisory
OpenCost ServiceKey Endpoint Unauthorized Credential Overwrite/Injection Vulnerability
1 rule 4 TTPs 2 IOCsOpenCost contains an unauthenticated file write vulnerability, tracked as GHSA-wmj8-9953-vff5, in its `/serviceKey` endpoint that allows remote attackers to overwrite the GCP service account key file (`key.json`) without any authentication or input validation, leading to service disruption, credential theft, and potential privilege escalation within Kubernetes clusters or GCP environments.
OpenCost: All versions
opencost
kubernetes
cloud
gcp
vulnerability
unauthenticated-access
file-write
1r
4t
2i