CVE-2019-3889: XSS
A reflected XSS vulnerability exists in authentication flow of OpenShift Container Platform. An attacker could use this flaw to steal authentication data by getting them to click on a malicious link.
Other sources
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3889?
CVE-2019-3889 has a vulnerability severity rating that should be assessed based on the potential impact to user authorization data.
How do I fix CVE-2019-3889?
To fix CVE-2019-3889, upgrade your OpenShift Container Platform to the latest version available that addresses this vulnerability.
What versions are affected by CVE-2019-3889?
CVE-2019-3889 affects OpenShift Container Platform versions 3.4 through 3.7 and 3.9 through 3.11, as well as version 4.1 and 4.2.
What type of vulnerability is CVE-2019-3889?
CVE-2019-3889 is classified as a reflected cross-site scripting (XSS) vulnerability.
Can CVE-2019-3889 be exploited remotely?
Yes, CVE-2019-3889 can be exploited remotely if users click on a malicious link crafted by an attacker.