A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
2019-07-11T19:15:13.377
2024-11-21T04:42:48.357
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | openshift_container_platform | ≤ 3.7 | Yes |
Application | redhat | openshift_container_platform | ≤ 3.11 | Yes |
Application | redhat | openshift_container_platform | 4.1 | Yes |
Application | redhat | openshift_container_platform | 4.2 | Yes |