CVE-2020-10715Improper Input Validation in Redhat Openshift

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 56.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 16
Latest updateMay 24

Description

A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5openshift/console3.11 and 4.x
NVDredhat/openshift4.04.3.5+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-7p43-3rw5-j59j: A content spoofing vulnerability was found in the openshift/console 32022-05-24
CVEList
CVE-2020-10715: A content spoofing vulnerability was found in the openshift/console 32020-09-16

📋Vendor Advisories

1
Red Hat
openshift/console: text injection on error page via crafted url2020-07-27

💬Community

1
Bugzilla
CVE-2020-10715 openshift/console: text injection on error page via crafted url2019-10-31
CVE-2020-10715 — Improper Input Validation in Redhat | cvebase