A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1813788 | Issue Tracking Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1813788 | Issue Tracking Vendor Advisory |
Configurations
History
21 Nov 2024, 05:11
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=1813788 - Issue Tracking, Vendor Advisory |
Information
Published : 2021-05-27 20:15
Updated : 2024-11-21 05:11
NVD link : CVE-2020-1761
Mitre link : CVE-2020-1761
CVE.ORG link : CVE-2020-1761
JSON object : View
Products Affected
redhat
- openshift
CWE