PT-2019-5406 · Red Hat · Openshift Container Platform

CVE-2019-3889

·

Publicado

2019-07-08

·

Atualizado

2023-03-01

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7, openshift-enterprise-3.9 through 3.11
Description A reflected XSS issue exists in the authorization flow, allowing an attacker to steal authorization data by tricking users into clicking a malicious link. This could enable a remote attacker to disclose authorization data using a specially crafted link.
Recommendations For openshift-online-3, update to a version that includes the fix for this issue. For openshift-enterprise-3.4 through 3.7, update to a version that includes the fix for this issue. For openshift-enterprise-3.9 through 3.11, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the authorization flow to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-02767
CVE-2019-3889
RHSA-2020:0795

Produtos afetados

Openshift Container Platform