Fedora Account System
Red Hat Associate
Red Hat Customer
The CatalogdHandler() in the OpenShift console is registered without authHandler (pkg/server/server.go:340). Furthermore, the CatalogdProxyConfig is the only proxy config that omits HeaderBlacklist: srv.ProxyHeaderDenyList (cmd/bridge/main.go:429-432), so the user's openshift-session-token cookie is forwarded verbatim to the catalogd service. Any unauthenticated network actor can GET /api/catalogd/<arbitrary-path> and the console pod will issue a TLS request to catalogd-service.openshift-catalogd.svc:443/<arbitrary-path>. This discloses the full operator-catalog index (intended to be cluster-internal) and provides a relay primitive into the openshift-catalogd namespace. Tested and reproduced on OCP 5.0 nightly cluster. Upstream: https://github.com/openshift/console File: pkg/server/server.go:340, pkg/server/server.go:859-868, cmd/bridge/main.go:429-432