Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-4981

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 5.4

Описание

A flaw was found in Red Hat Advanced Cluster Security (ACS). An unauthenticated remote attacker can exploit a vulnerability in the login interface's OAuth callback endpoint by crafting a malicious URL. This URL, containing unvalidated error and error_uri parameters, allows the attacker to display arbitrary error messages, leading to content spoofing. Furthermore, the attacker can redirect victims to malicious domains, effectively performing an open redirect under the guise of the trusted application's user interface.

Отчет

This Moderate impact vulnerability in Red Hat Advanced Cluster Security (ACS) allows an unauthenticated remote attacker to perform open redirect and content spoofing. By crafting a malicious URL with unvalidated parameters in the OAuth callback endpoint, an attacker can display arbitrary error messages and redirect users to malicious domains, appearing as the trusted application UI. This primarily affects user interaction with the login interface.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Security 4advanced-cluster-security/rhacs-main-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2452218rhacs: Red Hat Advanced Cluster Security (ACS): Open Redirect and Content Spoofing via OAuth callback endpoint

5.4 Medium

CVSS3

5.4 Medium

CVSS3