Impact
A flaw in the oauth-server component of Red Hat OpenShift Container Platform 4 allows an attacker to supply an unvalidated 'then' parameter in the grant approval handler. The parameter directs an authenticated user's browser to an attacker‑controlled site after they approve or deny a request, creating a phishing opportunity. The vulnerability does not expose OAuth tokens, authorization codes, or session credentials, but it can still trick users into providing sensitive information on a malicious page.
Affected Systems
The affected system is Red Hat OpenShift Container Platform 4, the oauth-server component of the platform. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score is 4.3, indicating low‑to‑moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated user interacting with the grant approval page. An attacker can craft a malicious URL, and once a user approves or denies the request, the browser is redirected to an attacker‑controlled site, enabling phishing attacks. No exploit code or special conditions are described beyond supply of the unvalidated parameter, and the vulnerability requires user interaction to be realized.
OpenCVE Enrichment