CVE-2018-10937Cross-site Scripting in RED HAT Openshift Container Platform

Severity
5.4MEDIUMNVD
CNA4.6
EPSS
0.3%
top 44.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 11
Latest updateMay 13

Description

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages1 packages

Also affects: Openshift Container Platform 3.11

🔴Vulnerability Details

2
GHSA
GHSA-7874-f8pp-9q35: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 32022-05-13
CVEList
CVE-2018-10937: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 32018-09-11

📋Vendor Advisories

1
Red Hat
tectonic-console: XSS Vulnerability in K8s API proxy2018-08-27

💬Community

1
Bugzilla
CVE-2018-10937 tectonic-console: XSS Vulnerability in K8s API proxy2018-08-27
CVE-2018-10937 — Cross-site Scripting in RED | cvebase