OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-04-11T19:00:00Z
Updated: 2024-08-05T16:04:11.828Z
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7534
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-04-11T19:29:00.213
Modified: 2024-11-21T03:32:06.147
Link: CVE-2017-7534
Redhat