PT-2019-11606 · Red Hat · Openshift Container Platform

Published

2019-08-02

·

Updated

2023-02-12

·

CVE-2019-10176

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: OpenShift Container Platform versions 3.11 and later
Description: A flaw was found in the cluster console component where the CSRF tokens remain static during a user's session. An attacker able to observe the value of this token could re-use it to perform a CSRF attack.
Recommendations: For OpenShift Container Platform versions 3.11 and later, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

CVE-2019-10176

Affected Products

Openshift Container Platform