Fedora Account System
Red Hat Associate
Red Hat Customer
The /locales/resource.json endpoint in the OpenShift console is registered without authHandler (pkg/server/server.go:544-546). The lng and ns query parameters are taken directly from user input with no sanitization (pkg/plugins/handlers.go:95-132). When ns does not have the "plugin__" prefix, the handler calls http.ServeFile with path.Join(p.PublicDir, "locales", lang, fmt.Sprintf("%s.json", namespace)). path.Join cleans ".." but does not confine the result under PublicDir. http.ServeFile's built-in ".." guard only inspects r.URL.Path, not the name argument. An unauthenticated attacker can read any *.json file from the pod filesystem, including ConfigMap-mounted plugin manifests and configuration files. When ns has the "plugin__" prefix, the unsanitized lang is injected into the request path sent to plugin services, enabling path traversal against every registered dynamic-plugin backend. Tested and reproduced on OCP 5.0 nightly cluster. Upstream: https://github.com/openshift/console File: pkg/server/server.go:544-546, pkg/plugins/handlers.go:95-132