← Retour aux CVEs
CVE-2019-3876
MEDIUM6.3
Description
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
Details CVE
Score CVSS v3.16.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie4/1/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0
Produits affectes
redhat:openshift_container_platform
Faiblesses (CWE)
CWE-352CWE-352
References
http://www.securityfocus.com/bid/107664(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2019:1851(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3876(secalert@redhat.com)
http://www.securityfocus.com/bid/107664(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2019:1851(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3876(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.