First published: Thu Feb 13 2020(Updated: )
OpenShift Container Platform (OCP) 3.11 was too permissive in the way it specified CORS allowed origins during installation. An attacker able to man-in-the-middle the connection between the user's browser and the openshift console could use this flaw to perform a phishing attack.
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat OpenShift Container Platform for IBM LinuxONE |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1802381 is considered high due to the potential for phishing attacks via man-in-the-middle exploitation.
To fix REDHAT-BUG-1802381, ensure that CORS allowed origins are configured securely in your OpenShift Container Platform deployment.
The potential impacts of REDHAT-BUG-1802381 include unauthorized access and exposure to phishing attacks targeting users of the OpenShift console.
OpenShift Container Platform version 3.11 is affected by REDHAT-BUG-1802381.
Yes, if exploited, REDHAT-BUG-1802381 can lead to data breaches through phishing tactics used by attackers.