Redhat Atomic-Openshift vulnerabilities
2 known vulnerabilities affecting redhat/atomic-openshift.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-10176MEDIUMCVSS 5.4vall versions fixed2019-08-02
CVE-2019-10176 [MEDIUM] CWE-352 CVE-2019-10176: A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
cvelistv5nvd
CVE-2019-10150MEDIUMCVSS 5.9v3.6.x - 4.0.02019-06-12
CVE-2019-10150 [MEDIUM] CWE-287 CVE-2019-10150: It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
cvelistv5nvd