Описание
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
Ссылки
- Vendor Advisory
- Issue TrackingVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00601
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-74
CWE-74
Связанные уязвимости
CVSS3: 4.3
redhat
почти 4 года назад
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
CVSS3: 4.3
github
почти 3 года назад
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
EPSS
Процентиль: 47%
0.00601
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-74
CWE-74