Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-10743


It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.


Published

2021-06-02T11:15:07.897

Last Modified

2024-11-21T04:55:58.640

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-358
  • Type: Secondary
    CWE-1021

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application elastic kibana - Yes
Application redhat openshift_container_platform 3.11.286 Yes
Application redhat openshift_container_platform 4.6.1 Yes

References