6.1
CVSSv3

CVE-2020-27816

Published: 02/12/2020 Updated: 04/12/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging console link damage. This flaw affects elasticsearch-operator-container versions prior to 4.7.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elastic kibana

redhat openshift container platform 4.0

Vendor Advisories

Synopsis Moderate: OpenShift Container Platform 4616 extras security update Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Container Platform release 4616 is now available withupdates to packages and images that fix several bugsRed Hat Product Security has rated this update as having ...