Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-4145

Опубликовано: 22 нояб. 2022
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

Отчет

This has been rated as low impact as there is no exploitability for this vulnerability, the vulnerability is a content injection in the error message that comes back as json data, an attacker cannot use this in any meaningful way to attack a victim, on top of that this attack would require user interaction of the victim to click the crafted URL, all of these points to this being not exploitable in any meaningful way.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshiftFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-74

EPSS

Процентиль: 47%
0.00601
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

CVSS3: 4.3
github
почти 3 года назад

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

EPSS

Процентиль: 47%
0.00601
Низкий

4.3 Medium

CVSS3