Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1342

Опубликовано: 13 фев. 2024
Источник: redhat
CVSS3: 4.2

Описание

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.

Отчет

While this CVE has been rejected and is no longer considered a vulnerability, Red Hat has updated the default CSRF protection for the Openshift Web Console to SameSite: Strict as a security hardening opportunity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshiftNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2259960openshift: existing Cross-Site Request Forgery protection insufficient for WebSocket creation

4.2 Medium

CVSS3

Связанные уязвимости

nvd
почти 2 года назад

Rejected reason: Unable to reproduce.

CVSS3: 5.4
github
почти 2 года назад

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.

4.2 Medium

CVSS3