Openshift Console vulnerabilities
2 known vulnerabilities affecting openshift/console.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2020-1761MEDIUMCVSS 6.1vopenshift/console-42021-05-27
CVE-2020-1761 [MEDIUM] CWE-358 CVE-2020-1761: A flaw was found in the OpenShift web console, where the access token is stored in the browser's loc
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
cvelistv5nvd
CVE-2020-10715MEDIUMCVSS 4.3v3.11 and 4.x2020-09-16
CVE-2020-10715 [MEDIUM] CWE-20 CVE-2020-10715: A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows a
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.
cvelistv5nvd