Unable to reproduce.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Oct 2024 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Openshift: existing cross-site request forgery protection insufficient for websocket creation | openshift: existing Cross-Site Request Forgery protection insufficient for WebSocket creation |
| References |
|
Mon, 14 Oct 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 14 Oct 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF. | Unable to reproduce. |
| CPEs | ||
| Vendors & Products |
Redhat
Redhat openshift |
Projects
Sign in to view the affected projects.
Status: REJECTED
Assigner: redhat
Published:
Updated: 2024-10-14T22:00:07.768Z
Reserved: 2024-02-07T22:26:19.404Z
Link: CVE-2024-1342
Updated:
Status : Rejected
Published: 2024-02-16T16:15:57.543
Modified: 2024-10-14T22:15:03.180
Link: CVE-2024-1342
OpenCVE Enrichment
No data.
Weaknesses