Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1342

Опубликовано: 13 фев. 2024
Источник: redhat

Описание

No description is available for this CVE.

Отчет

This CVE has been marked as Rejected by the assigning CNA.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshiftNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2259960openshift: existing Cross-Site Request Forgery protection insufficient for WebSocket creation

Связанные уязвимости

nvd
больше 2 лет назад

Rejected reason: Unable to reproduce.

CVSS3: 5.4
github
больше 2 лет назад

A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF.