Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-0188

Опубликовано: 24 апр. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
Версия до 1.2.7 (включая)
cpe:2.3:a:redhat:openshift:*:*:*:*:enterprise:*:*:*
Версия от 2.0 (включая) до 2.0.5 (включая)

EPSS

Процентиль: 59%
0.00383
Низкий

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

redhat
почти 12 лет назад

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

github
больше 3 лет назад

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.

EPSS

Процентиль: 59%
0.00383
Низкий

7.5 High

CVSS2

Дефекты

CWE-287