When skupper (RHSI) is initialized with the console-enabled and with console-auth set to openshift, it configures the openshift oauth-proxy with a static cookie-secret 'SECRET'. This has been shown to allow forged cookies to be used to bypass authentication for the skupper console.
This issue has been addressed in the following products: Service Interconnect 1.4 for RHEL 9 Via RHSA-2024:4865 https://access.redhat.com/errata/RHSA-2024:4865
This issue has been addressed in the following products: Service Interconnect 1 for RHEL 9 Via RHSA-2024:4871 https://access.redhat.com/errata/RHSA-2024:4871