Zurück zur CVE-Übersicht
CVE-2026-49332
HIGH(8.5)CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Risk Signal Score21/100 — NIEDRIG
- CVSS 8.5 — Hoch
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.5%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
8.5
Technische Schwere
Beschreibung
A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks normalize both variants to the same variable, allowing an authenticated low-privilege user to smuggle a forged identity that may override the legitimate authenticated identity in the upstream application.
Referenzen
- https://access.redhat.com/errata/RHSA-2026:50681
- https://access.redhat.com/errata/RHSA-2026:50758
- https://access.redhat.com/errata/RHSA-2026:51007
- https://access.redhat.com/errata/RHSA-2026:51013
- https://access.redhat.com/errata/RHSA-2026:51022
- https://access.redhat.com/errata/RHSA-2026:51025
- https://access.redhat.com/errata/RHSA-2026:51038
- https://access.redhat.com/errata/RHSA-2026:54188
- https://access.redhat.com/errata/RHSA-2026:54206
- https://access.redhat.com/errata/RHSA-2026:56912