PT-2019-6836 · Red Hat · Openshift Enterprise
Jeremy Choi
·
Published
2019-12-30
·
Updated
2023-02-13
·
CVE-2013-0196
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenShift Enterprise version 1.2
Description
A CSRF issue was found in the web console, which uses 'Basic authentication', and the REST API lacks a CSRF attack protection mechanism. This allows an attacker to obtain credentials and the Authorization: header when requesting the REST API via a web browser.
Recommendations
For OpenShift Enterprise version 1.2, consider implementing a CSRF attack protection mechanism for the REST API to prevent unauthorized access. As a temporary workaround, restrict access to the REST API to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openshift Enterprise