Back

MEDIUM

OpenShift Enterprise and Online vulnerable to CSRF attack with REST API

Published Dec 30, 2019

Description

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 30, 2019
Updated Aug 6, 2024
Reserved Dec 6, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Sep 5, 2014