CVE-2019-3876
published 2019-04-01CVE-2019-3876: A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing…
PriorityP428medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.67%
48.0th percentile
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | openshift_oauth-apiserver | >= 3.0 < 3.11 | 3.11 |
| red_hat | web-console | — | — |
| redhat | openshift_container_platform | 3.0 – 3.11 | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv3.05.0MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
web-console: XSS in OAuth server /oauth/token/request endpoint
vendor_redhat·2019-03-27·CVSS 6.3
CVE-2019-3876 [MEDIUM] CWE-352 web-console: XSS in OAuth server /oauth/token/request endpoint
web-console: XSS in OAuth server /oauth/token/request endpoint
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
Statement: This issue affects the OAuth server shipped in OpenShift Container Platform version v3.0 throug
GHSA
Withdrawn Advisory: OpenShift OAuth Server XSS Vulnerability
ghsa·2022-05-13
CVE-2019-3876 [MEDIUM] CWE-352 Withdrawn Advisory: OpenShift OAuth Server XSS Vulnerability
Withdrawn Advisory: OpenShift OAuth Server XSS Vulnerability
## Withdrawn Advisory
This advisory has been withdrawn because the vulnerability does not affect a package in one of the GitHub Advisory Database's [supported ecosystems](https://github.com/github/advisory-database/blob/main/README.md#supported-ecosystems). This link is maintained to preserve external references.
## Original Description
A flaw was found in the `/oauth/token/request` custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9433 libvpx: Use-after-free in vp8_deblock() in vp8/common/postproc.c
bugzilla·2020-01-08·CVSS 6.5
CVE-2019-9433 [MEDIUM] CVE-2019-9433 libvpx: Use-after-free in vp8_deblock() in vp8/common/postproc.c
CVE-2019-9433 libvpx: Use-after-free in vp8_deblock() in vp8/common/postproc.c
In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
Upstream issue:
https://chromium-review.googlesource.com/c/webm/libvpx/%2B/1070753
Upstream patch:
https://github.com/webmproject/libvpx/commit/52add5896661d186dec284ed646a4b33b607d2c7
References:
http://www.openwall.com/lists/oss-security/2019/10/25/17
http://www.openwall.com/lists/oss-security/2019/10/27/1
http://www.openwall.com/lists/oss-security/2019/11/07/1
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3876
Bugzilla
CVE-2019-9232 libvpx: Out of bounds read in vp8_norm table
bugzilla·2020-01-08·CVSS 7.5
CVE-2019-9232 [HIGH] CVE-2019-9232 libvpx: Out of bounds read in vp8_norm table
CVE-2019-9232 libvpx: Out of bounds read in vp8_norm table
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Upstream issue:
https://chromium-review.googlesource.com/c/webm/libvpx/%2B/1395793
Upstream patch:
https://github.com/webmproject/libvpx/commit/46e17f0cb4a80b36755c84b8bf15731d3386c08f
References:
http://www.openwall.com/lists/oss-security/2019/10/25/17
http://www.openwall.com/lists/oss-security/2019/10/27/1
http://www.openwall.com/lists/oss-security/2019/11/07/1
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:3876 https://access.redhat.
Bugzilla
CVE-2019-3876 web-console: XSS in OAuth server /oauth/token/request endpoint
bugzilla·2019-03-20·CVSS 6.3
CVE-2019-3876 [MEDIUM] CVE-2019-3876 web-console: XSS in OAuth server /oauth/token/request endpoint
CVE-2019-3876 web-console: XSS in OAuth server /oauth/token/request endpoint
A flaw was found in Openshift OAuth server. An XSS vulnerability in oauth/token/request endpoint that could allow to retrieve a token for CLI usage when using non default configs.
Discussion:
Acknowledgments:
Name: Mo Khan (Red Hat)
---
Statement:
This issue affects the OAuth server shipped in OpenShift Container Platform version v3.0 through v3.11. Red Hat Product Security has rated this issue as having a security impact of Moderate.
For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
---
Mitigation:
Since at least v3.4, the OpenShift documentation [1] has specified the format for corsAllowedOrigins to accurately match inte
2019-04-01
Published