CVE-2017-7534
published 2018-04-11CVE-2017-7534: OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.56%
43.0th percentile
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
| redhat | openshift | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openshift: XSS in log viewer for a pod
vendor_redhat·2018-04-10·CVSS 5.4
CVE-2017-7534 [MEDIUM] CWE-79 openshift: XSS in log viewer for a pod
openshift: XSS in log viewer for a pod
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
OpenShift Enterprise is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Package: Security (Red Hat OpenShift Enterprise 2) - Not affected
Package: Security (Red Hat OpenShift Enterprise 3) - Affected
GHSA
GHSA-7wp7-h784-jvqx: OpenShift Enterprise version 3
ghsa_unreviewed·2022-05-13
CVE-2017-7534 [MEDIUM] CWE-79 GHSA-7wp7-h784-jvqx: OpenShift Enterprise version 3
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
No detection rules found.
No public exploits indexed.
2018-04-11
Published