Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-3889

Опубликовано: 08 июл. 2019
Источник: redhat
CVSS3: 4.6

Описание

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.

A reflected XSS vulnerability exists in the authentication flow of the OpenShift Container Platform. An attacker could use this flaw to steal authentication data by having users click a malicious link.

Отчет

Since the HTTP Response "Content Type" is "text/plain" most browsers won't execute any Javascipt in the response content. However if an attacker can trick a user into loading the response in an iFrame it is possible to exploit this vulnerability. Appropriate Cross Origin Resource (CORS) Allowed Domain configuration in OCP 3 should prevent an attacker from getting any response from a attacker hosted domain. Therefore make sure that corsAllowedDomains is specified correctly in your OCP 3 master-config.yaml. See [1] for more details on an issue with corsAllowedDomains in OCP 3. [1] https://bugzilla.redhat.com/show_bug.cgi?id=1694913 Also content sniffing browsers [2] do execute Javascript even when the "Content Type" HTTP Response header is set to "text/plain". [2] https://en.wikipedia.org/wiki/Content_sniffing

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10atomic-openshiftFix deferred
Red Hat OpenShift Container Platform 3.4atomic-openshiftWill not fix
Red Hat OpenShift Container Platform 3.5atomic-openshiftWill not fix
Red Hat OpenShift Container Platform 3.6atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.7atomic-openshiftOut of support scope
Red Hat OpenShift Container Platform 3.9atomic-openshiftFix deferred
Red Hat OpenShift Container Platform 3.11atomic-openshiftFixedRHSA-2020:079520.03.2020
Red Hat OpenShift Container Platform 4.1openshift4/ose-hypershiftFixedRHSA-2019:372207.11.2019
Red Hat OpenShift Container Platform 4.2openshift4/ose-oauth-server-rhel7FixedRHSA-2019:377013.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1693499atomic-openshift: reflected XSS in authentication flow

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 6 лет назад

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.

CVSS3: 5.4
github
больше 3 лет назад

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.

CVSS3: 5.4
fstec
больше 6 лет назад

Уязвимость корпоративной платформы Red Hat OpenShift Container Platform, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю раскрыть авторизационные данные

4.6 Medium

CVSS3