Описание
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
Ссылки
- Vendor Advisory
- Issue TrackingVendor Advisory
- Vendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
EPSS
Процентиль: 24%
0.00081
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-74
CWE-74
Связанные уязвимости
CVSS3: 4.3
redhat
около 3 лет назад
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
CVSS3: 4.3
github
больше 2 лет назад
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
EPSS
Процентиль: 24%
0.00081
Низкий
4.3 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
CWE-74
CWE-74