VulnerabilityModified
CVE-2017-7534
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods.
MEDIUM 5.4EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.53% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/openshift
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.