Логотип exploitDog
bind:CVE-2023-4456
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-4456

Количество 3

Количество 3

redhat логотип

CVE-2023-4456

больше 2 лет назад

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2023-4456

больше 2 лет назад

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-ccmh-37rx-6pp5

больше 2 лет назад

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2023-4456

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4456

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад
github логотип
GHSA-ccmh-37rx-6pp5

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached.

CVSS3: 5.7
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу