Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1761

Опубликовано: 27 мая 2021
Источник: nvd
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:openshift:*:*:*:*:*:*:*:*
Версия до 4.0 (исключая)

EPSS

Процентиль: 37%
0.00157
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-358
NVD-CWE-Other

Связанные уязвимости

CVSS3: 6.3
redhat
почти 6 лет назад

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.

CVSS3: 6.1
github
больше 3 лет назад

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.

EPSS

Процентиль: 37%
0.00157
Низкий

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-358
NVD-CWE-Other