CVE-2018-10937: XSS
Published Sep 11, 2018
·Updated
A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Affected Software
1 affected component
redhat OpenShift Container Platform=3.11
Event History
Sep 11, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-10937?
CVE-2018-10937 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2018-10937?
To fix CVE-2018-10937, update to the latest patched version of Red Hat OpenShift Container Platform 3.11.
3
What type of vulnerability is CVE-2018-10937?
CVE-2018-10937 is a cross-site scripting (XSS) vulnerability.
4
Who is affected by CVE-2018-10937?
CVE-2018-10937 affects users of Red Hat OpenShift Container Platform version 3.11.
5
What can an attacker do exploiting CVE-2018-10937?
An attacker exploiting CVE-2018-10937 can perform actions on the Kubernetes API as the victim if they can create pods.