PT-2019-5406 · Red Hat · Openshift Container Platform
CVE-2019-3889
·
Publicado
2019-07-08
·
Atualizado
2023-03-01
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7, openshift-enterprise-3.9 through 3.11
Description
A reflected XSS issue exists in the authorization flow, allowing an attacker to steal authorization data by tricking users into clicking a malicious link. This could enable a remote attacker to disclose authorization data using a specially crafted link.
Recommendations
For openshift-online-3, update to a version that includes the fix for this issue.
For openshift-enterprise-3.4 through 3.7, update to a version that includes the fix for this issue.
For openshift-enterprise-3.9 through 3.11, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the authorization flow to minimize the risk of exploitation.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Openshift Container Platform