Cluster-version-operator metrics port exposed all the metrics information without any authorization
Issue
-
When we exposed the master node on port 9099/metrics, it shows all the metrics details without authorization and this allows unauthenticated external access.
-
The cluster-version-operator namespace contains a service exposed on port 9099 for metrics information.
Environment
- Red Hat OpenShift Container Platform 4.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.