Unable to reproduce.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Oct 2024 23:15:00 +0000

Type Values Removed Values Added
Title Openshift: existing cross-site request forgery protection insufficient for websocket creation openshift: existing Cross-Site Request Forgery protection insufficient for WebSocket creation
References

Mon, 14 Oct 2024 22:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Mon, 14 Oct 2024 22:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in OpenShift. The existing Cross-Site Request Forgery (CSRF) protections in place do not properly protect GET requests, allowing for the creation of WebSockets via CSRF. Unable to reproduce.
CPEs cpe:/a:redhat:openshift:4
Vendors & Products Redhat
Redhat openshift

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: REJECTED

Assigner: redhat

Published:

Updated: 2024-10-14T22:00:07.768Z

Reserved: 2024-02-07T22:26:19.404Z

Link: CVE-2024-1342

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2024-02-16T16:15:57.543

Modified: 2024-10-14T22:15:03.180

Link: CVE-2024-1342

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-02-13T00:00:00Z

Links: CVE-2024-1342 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses