CORS Misconfiguration in OpenShift Container Platform by Red Hat
CVE-2020-1741
5.9MEDIUM
What is CVE-2020-1741?
A flaw in OpenShift Container Platform 3.11 originates from overly permissive CORS allowed origins configurations during installation. This vulnerability allows attackers to man-in-the-middle the communication between a user's browser and the OpenShift console. By exploiting this, an attacker could initiate phishing attacks, potentially compromising user data and posing serious risks to data confidentiality. It highlights the importance of properly configuring CORS settings to mitigate such security threats.
Affected Version(s)
openshift-ansible openshift-ansible-3.11