First published: Wed Nov 13 2019(Updated: )
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Origin | <=2014-08-13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3592 is classified as a moderate severity vulnerability.
To fix CVE-2014-3592, upgrade to a version of Red Hat OpenShift Origin later than 2014-08-13 that addresses the vulnerability.
CVE-2014-3592 is an example of stored cross-site scripting (XSS) due to improperly validated team names.
Red Hat OpenShift Origin versions up to and including 2014-08-13 are affected by CVE-2014-3592.
CVE-2014-3592 could allow attackers to execute malicious scripts in the context of users' browsers, leading to potential data theft.