OpenShift Container Platform CSRF Token Vulnerability Affecting Red Hat
CVE-2019-10176

4.2MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
2 August 2019

What is CVE-2019-10176?

A vulnerability has been identified in OpenShift Container Platform, specifically in its cluster console component, where CSRF tokens remain static throughout a user's session. This flaw allows attackers who can observe these tokens to exploit them and perform unauthorized actions on behalf of the user, potentially compromising user sessions and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

atomic-openshift all versions fixed

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.