Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4crf-28c7-v4gr

Опубликовано: 21 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.5
CVSS3: 8

Описание

Openshift Console insufficient entropy vulnerability

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

Пакеты

Наименование

github.com/openshift/console

go
Затронутые версииВерсия исправления

<= 6.0.6

Отсутствует

EPSS

Процентиль: 71%
0.00664
Низкий

5.5 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 8
redhat
больше 1 года назад

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

CVSS3: 8
nvd
больше 1 года назад

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

EPSS

Процентиль: 71%
0.00664
Низкий

5.5 Medium

CVSS4

8 High

CVSS3

Дефекты

CWE-331