Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grwq-5xxg-8mfg

Опубликовано: 16 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.

5.4 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 4.2
redhat
почти 2 года назад

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.

nvd
почти 2 года назад

Rejected reason: Unable to reproduce.

5.4 Medium

CVSS3

Дефекты

CWE-352