PT-2016-5666 · Red Hat · Red Hat Openshift Enterprise
Jordan Liggitt
·
Publicado
2016-06-08
·
Atualizado
2023-02-12
·
CVE-2016-3703
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat OpenShift Enterprise versions 3.1 through 3.2
Description
The issue arises from improper validation of the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod. This allows remote attackers to access API credentials in the web browser localStorage via an access token in the query parameter.
Recommendations
For Red Hat OpenShift Enterprise versions 3.1 through 3.2, consider restricting anonymous access to service/proxy or pod/proxy APIs to minimize the risk of exploitation. As a temporary workaround, restrict access to the localStorage and ensure proper validation of request origins to prevent unauthorized access to API credentials.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Red Hat Openshift Enterprise