Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3207

Опубликовано: 07 июл. 2020
Источник: redhat
CVSS3: 5.3

Описание

In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

A flaw was found in OpenShift Origin. This vulnerability may allow unauthorized access and manipulation of the console via interception and manipulation of cookies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel8Not affected
Red Hat OpenShift Container Platform 4openshift4/ose-testsNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/cluster-network-addons-operatorNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/cluster-network-addons-operator-rhel9Not affected
Red Hat OpenStack Platform 16.2osp-director-provisioner-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-311
Дефект:
CWE-614
https://bugzilla.redhat.com/show_bug.cgi?id=2105433github.com/openshift/origin: Insecure cookies in Openshift Origin in github.com/openshift/origin

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.

CVSS3: 5.3
github
больше 3 лет назад

Insecure cookies in Openshift Origin

5.3 Medium

CVSS3