A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T06:46:30.893Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2020-1761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-27T20:15:08.030

Modified: 2024-11-21T05:11:19.867

Link: CVE-2020-1761

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-02-11T00:00:00Z

Links: CVE-2020-1761 - Bugzilla

cve-icon OpenCVE Enrichment

No data.