Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-946m-r2cc-x4j3

Опубликовано: 17 окт. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.5

Описание

An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.

An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.

EPSS

Процентиль: 40%
0.00184
Низкий

3.5 Low

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 3
redhat
почти 9 лет назад

An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.

CVSS3: 3.5
nvd
больше 3 лет назад

An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.

EPSS

Процентиль: 40%
0.00184
Низкий

3.5 Low

CVSS3

Дефекты

CWE-20