CVE-2018-10937
published 2018-09-11CVE-2018-10937: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use…
PriorityP426medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
1.08%
61.3th percentile
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7874-f8pp-9q35: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3
ghsa_unreviewed·2022-05-13
CVE-2018-10937 [MEDIUM] CWE-79 GHSA-7874-f8pp-9q35: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Red Hat
tectonic-console: XSS Vulnerability in K8s API proxy
vendor_redhat·2018-08-27·CVSS 4.6
CVE-2018-10937 [MEDIUM] CWE-79 tectonic-console: XSS Vulnerability in K8s API proxy
tectonic-console: XSS Vulnerability in K8s API proxy
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Package: tectonic-console (Red Hat OpenShift Container Platform 3.10) - Not affected
Package: tectonic-console (Red Hat OpenShift Container Platform 3.11) - Not affected
Package: tectonic-console (Red Hat OpenShift Container Platform 3.2) - Not affected
Package: tectonic-console (Red Hat OpenShift Container Platform 3.3) - Not affected
Package: tectonic-console (Red Hat OpenShift Container Platform 3.4) - Not affected
Package: tectonic-console (Red Hat OpenShift Container Platform 3.5) - Not affected
Package: tectoni
No detection rules found.
No public exploits indexed.
http://www.securityfocus.com/bid/105190https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10937https://github.com/openshift/console/commit/d56666852da6e7309a2e63a49f49a72ff66d309chttps://github.com/openshift/console/pull/461http://www.securityfocus.com/bid/105190https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10937https://github.com/openshift/console/commit/d56666852da6e7309a2e63a49f49a72ff66d309chttps://github.com/openshift/console/pull/461
2018-09-11
Published