Описание
No description is available for this CVE.
Отчет
This CVE has been marked as Rejected by the assigning CNA.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift | Not affected |
Показывать по
10
Дополнительная информация
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2259960openshift: existing Cross-Site Request Forgery protection insufficient for WebSocket creation
Связанные уязвимости
CVSS3: 5.4
github
больше 2 лет назад
A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.