CVE-2024-6508 Information
Aug 22, 2024
cve
Description
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
Reference
https://access.redhat.com/security/cve/CVE-2024-6508 https://bugzilla.redhat.com/show_bug.cgi?id=2295777
Share on: