Database/Container, Kubernetes & orchestration
OpenRun: redirect URL restrictions can be bypassed, giving an open redirect on the deploy console
Impact
OpenRun is a self-hosted GitOps platform that deploys apps to Docker or Kubernetes, so its web console is an operator-facing control surface with credentials for the clusters it pushes to. Before 0.17.7 its redirect URL restrictions can be bypassed, so an attacker-supplied link routed through the console sends an operator to an arbitrary external site. On its own this yields no access to the cluster: it is a phishing and credential-harvesting primitive against the people who hold deploy rights, and the record describes no code execution or token theft. Treat it as hygiene on an in-scope control-plane component rather than an urgent cluster exposure.
Who can reach it
Remote and unauthenticated to trigger, but it needs a victim to follow the crafted link - the useful target is an operator with an OpenRun session, so the real precondition is getting a link in front of someone who can deploy.
What to do
Upgrade OpenRun to 0.17.7, which carries the fix. That is a restart of the OpenRun service; running workloads already deployed to Docker or Kubernetes are not touched, and no node drain or reboot is involved.
References
Related entries
- AWS EFS CSI Driver: crafted volumeHandle causes recursive deletion of directories on another filesystemCVE-2026-85781 · Amazon EFS CSI Driver (volume deletion, access point ownership check)Medium
- CRI-O: All pod processes share one memory cgroup, so a workload OOM kills conmon and destabilises the nodeCVE-2019-14891 · CRI-OMedium
- containerd: Crafted image can change Unix file permissions of existing host files during extractionCVE-2021-32760 · containerdMedium
- Istio: A user with CREATE on Gateway API resources escalates privilege in istiodCVE-2022-21701 · IstioMedium
- runc: Rootless runc leaves /sys/fs/cgroup writable inside the containerCVE-2023-25809 · runcMedium
- Slurm: Authentication-handling mistake in stepmgr lets an attacker execute processes under other users' jobsCVE-2024-48936 · SlurmMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.