PT-2026-23642 · Openshift · Openshift

Mdavis

·

Publicado

2026-03-06

·

Atualizado

2026-03-06

·

CVE-2026-28675

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSift versions prior to 1.6.3-alpha
Description OpenSift is an AI study tool that uses semantic search and generative AI to analyze large datasets. Prior to version 1.6.3-alpha, certain API endpoints returned raw exception strings to clients, potentially exposing sensitive implementation details. Additionally, login token material was exposed in the user interface and token rotation output. The vulnerable endpoints include those that handle exceptions and token management. The exposed token material includes information related to user authentication. The token is exposed in UI responses and token rotation output.
Recommendations Update to version 1.6.3-alpha or later.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28675
GHSA-667G-RVCJ-W976

Produtos afetados

Openshift