5.8
CVSSv2

CVE-2019-10176

Published: 02/08/2019 Updated: 17/09/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openshift container platform 3.11

redhat openshift container platform 4.1

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 4116 security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-console-container is nowavailable for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a secu ...
Synopsis Moderate: OpenShift Container Platform 311 openshift-enterprise-console-container security update Type/Severity Security Advisory: Moderate Topic An update for openshift-enterprise-console-container is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated t ...
Impact: Moderate Public Date: 2019-07-09 CWE: CWE-352 Bugzilla: 1712569: CVE-2019-10176 atomic-openshif ...