CVE-2021-3442: Input Validation
A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidentiality.
Other sources
During the test we found that there are no input validation for user input, and its possible to inject scripts into text box in the following links
https://3scale-admin.apps.rhoam-pentest.ofop.p1.openshiftapps.com/site/emails/edit https://3scale-admin.apps.rhoam-pentest.ofop.p1.openshiftapps.com/p/admin/backendapis/2 The XSS attack is possible only by an authenticated user so the severity is low
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3442?
CVE-2021-3442 is considered a high-severity vulnerability due to the potential for data confidentiality breaches.
How do I fix CVE-2021-3442?
To fix CVE-2021-3442, ensure that user input is properly validated and sanitize all inputs in the affected Red Hat OpenShift API Management version.
What types of attacks can CVE-2021-3442 enable?
CVE-2021-3442 can enable XSS (Cross-Site Scripting) attacks, allowing attackers to inject malicious scripts into web applications.
Who is affected by CVE-2021-3442?
CVE-2021-3442 affects users running Red Hat OpenShift API Management version 2.9.1.
What is the potential impact of CVE-2021-3442?
The potential impact of CVE-2021-3442 includes unauthorized access to sensitive data due to XSS vulnerabilities.