CVE-2016-3703 Information
Feb 14, 2021
cve
Description
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://access.redhat.com/errata/RHSA-2016:1094 https://access.redhat.com/errata/RHSA-2016:1095
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: