A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
References
Link | Resource |
---|---|
https://github.com/openshift/console/pull/461 | Third Party Advisory |
https://github.com/openshift/console/commit/d56666852da6e7309a2e63a49f49a72ff66d309c | Exploit Third Party Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10937 | Issue Tracking Third Party Advisory |
http://www.securityfocus.com/bid/105190 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2018-09-11 09:29
Updated : 2019-10-09 16:33
NVD link : CVE-2018-10937
Mitre link : CVE-2018-10937
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
redhat
- openshift_container_platform