Reflected XSS Vulnerability in OpenShift Container Platform by Red Hat
CVE-2019-3889
4.6MEDIUM
What is CVE-2019-3889?
An issue has been identified in the OpenShift Container Platform that allows an attacker to exploit reflected XSS within the authorization flow. This vulnerability can allow unauthorized users to hijack user sessions by enticing users to click on specially crafted malicious links. By manipulating the browser's response, an attacker may extract sensitive authorization data, leading to potential unauthorized access to a user's account.
Affected Version(s)
atomic-openshift openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11