Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2w57-4v2r-38c4

Опубликовано: 05 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

EPSS

Процентиль: 30%
0.0011
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

redhat
больше 11 лет назад

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

CVSS3: 6.5
nvd
около 6 лет назад

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

EPSS

Процентиль: 30%
0.0011
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-352