First published: Tue Sep 11 2018(Updated: )
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform | =3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10937 is classified as a moderate severity vulnerability.
To fix CVE-2018-10937, update to the latest patched version of Red Hat OpenShift Container Platform 3.11.
CVE-2018-10937 is a cross-site scripting (XSS) vulnerability.
CVE-2018-10937 affects users of Red Hat OpenShift Container Platform version 3.11.
An attacker exploiting CVE-2018-10937 can perform actions on the Kubernetes API as the victim if they can create pods.