Advisory Published
Updated

REDHAT-BUG-1802381

First published: Thu Feb 13 2020(Updated: )

OpenShift Container Platform (OCP) 3.11 was too permissive in the way it specified CORS allowed origins during installation. An attacker able to man-in-the-middle the connection between the user's browser and the openshift console could use this flaw to perform a phishing attack.

Affected SoftwareAffected VersionHow to fix
Red Hat OpenShift Container Platform for IBM LinuxONE

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of REDHAT-BUG-1802381?

    The severity of REDHAT-BUG-1802381 is considered high due to the potential for phishing attacks via man-in-the-middle exploitation.

  • How do I fix REDHAT-BUG-1802381?

    To fix REDHAT-BUG-1802381, ensure that CORS allowed origins are configured securely in your OpenShift Container Platform deployment.

  • What are the potential impacts of REDHAT-BUG-1802381?

    The potential impacts of REDHAT-BUG-1802381 include unauthorized access and exposure to phishing attacks targeting users of the OpenShift console.

  • Which version of OpenShift Container Platform is affected by REDHAT-BUG-1802381?

    OpenShift Container Platform version 3.11 is affected by REDHAT-BUG-1802381.

  • Can REDHAT-BUG-1802381 lead to data breaches?

    Yes, if exploited, REDHAT-BUG-1802381 can lead to data breaches through phishing tactics used by attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203