PT-2019-5406 · Red Hat · Openshift Container Platform

Published

2019-07-08

·

Updated

2023-03-01

·

CVE-2019-3889

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7, openshift-enterprise-3.9 through 3.11
Description A reflected XSS issue exists in the authorization flow, allowing an attacker to steal authorization data by tricking users into clicking a malicious link. This could enable a remote attacker to disclose authorization data using a specially crafted link.
Recommendations For openshift-online-3, update to a version that includes the fix for this issue. For openshift-enterprise-3.4 through 3.7, update to a version that includes the fix for this issue. For openshift-enterprise-3.9 through 3.11, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the authorization flow to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2020-02767
CVE-2019-3889
RHSA-2020:0795

Affected Products

Openshift Container Platform