First published: Tue Nov 22 2022(Updated: )
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openshift Container Platform | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4145 is a content spoofing vulnerability found in OpenShift's OAuth endpoint.
CVE-2022-4145 has a severity rating of 5.3 (medium).
The affected software is Redhat Openshift Container Platform 4.0.
CVE-2022-4145 is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')).
An attacker can exploit CVE-2022-4145 by injecting text into a webpage to obfuscate a phishing operation.