CVE-2019-10176
published 2019-08-02CVE-2019-10176: A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain…
PriorityP425medium5.4CVSS 3.0
AVNACLPRNUIRSUCLILAN
EPSS
0.55%
42.3th percentile
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | atomic-openshift | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g38-6996-78pm: A flaw was found in OpenShift Container Platform, versions 3
ghsa_unreviewed·2022-05-24
CVE-2019-10176 [MEDIUM] CWE-352 GHSA-2g38-6996-78pm: A flaw was found in OpenShift Container Platform, versions 3
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
Red Hat
atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
vendor_redhat·2019-07-09·CVSS 4.2
CVE-2019-10176 [MEDIUM] CWE-352 atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
Statement: OpenShift Container Platform versions prior to 3.11 do not c
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-15052 gradle: sends authentication credentials originally destined for the configured host
bugzilla·2019-09-27·CVSS 9.8
CVE-2019-15052 [CRITICAL] CVE-2019-15052 gradle: sends authentication credentials originally destined for the configured host
CVE-2019-15052 gradle: sends authentication credentials originally destined for the configured host
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.
References:
https://github.com/gradle/gradle/issues/10278
https://github.com/gradle/gradle/pull/10176
https://github.com/gradle/gradle/security/advisories/GHSA-4cwg-f7qc-6r95
Discussion:
Created gradle tracking bugs for this issue:
Affects: epel-6 [bug 1756390]
Affects: fedora-all [bug 1756389]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://ac
Bugzilla
CVE-2019-10176 atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
bugzilla·2019-05-21·CVSS 4.2
CVE-2019-10176 [MEDIUM] CVE-2019-10176 atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
CVE-2019-10176 atomic-openshift: CSRF tokens not refreshing while user is logged in and are exposed in the URL
A flaw was found in atomic-openshift. CSRF tokens are not refreshing while a user is logged in, and they are exposed in the URL. This may allow attackers to perform CSRF attacks successfully.
Discussion:
Statement:
OpenShift Container Platform versions prior to 3.11 do not contain the affected "cluster console" component and are not vulnerable to this flaw.
---
Acknowledgments:
Name: Jeremy Choi (Red Hat)
---
From OWASP docs: https://github.com/OWASP/CheatSheetSeries/blob/master/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.md
firstly, the docs indicate that a CSRF per session is adequate in general
- "Any state changing operation requires a secure random
https://access.redhat.com/errata/RHSA-2019:2792https://access.redhat.com/errata/RHSA-2019:4053https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10176https://access.redhat.com/errata/RHSA-2019:2792https://access.redhat.com/errata/RHSA-2019:4053https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10176
2019-08-02
Published