OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1443003 | Issue Tracking |
http://www.securityfocus.com/bid/103754 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2018-04-11 12:29
Updated : 2019-10-09 16:29
NVD link : CVE-2017-7534
Mitre link : CVE-2017-7534
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
redhat
- openshift