web-console: XSS in OAuth server /oauth/token/request endpoint
Published Apr 1, 2019
6.3
MEDIUMCVSS 3.1
EPSS 0.67%
Description
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
Affected products
-
- Version affects OpenShift Container Platform version v3.0 through v3.11StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Red Hat | Web-Console | n/a |
|
- ≥ 3.0 · ≤ 3.11
No data.
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.129-1.git.0.bd4f2d5.el7
Fixed · RHSA-2019:1851
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1560870549-1.el7
Fixed · RHSA-2019:1851
Red Hat OpenShift Container Platform 3.10
atomic-openshift
Fix deferred
Red Hat OpenShift Container Platform 3.4
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.5
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.6
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.7
atomic-openshift
Out of support scope
Red Hat OpenShift Container Platform 3.9
atomic-openshift
Fix deferred
Red Hat OpenShift Container Platform 4
openshift
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.129-1.git.0.bd4f2d5.el7 | Fixed | RHSA-2019:1851 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1560870549-1.el7 | Fixed | RHSA-2019:1851 |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 3.4 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.5 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.6 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.7 | atomic-openshift | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift | Not affected | n/a |
github.com/openshift/oauth-apiserver
Go
Introduced 3.0 Fixed 3.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/openshift/oauth-apiserver | 3.0 | 3.11 |
Remediation
Red Hat statement
This issue affects the OAuth server shipped in OpenShift Container Platform version v3.0 through v3.11. Red Hat Product Security has rated this issue as having a security impact of Moderate. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Red Hat mitigation
Since at least v3.4, the OpenShift documentation [1] has specified the format for corsAllowedOrigins to accurately match intended hostnames. Since at least v3.7, installs will default to use the correct regular expression formatted variables. Earlier versions may be configured with plain strings, a configuration which will persist across cluster upgrades, opening them to cross origin vulnerabilities such as this. At a minimum, you should ensure that the corsAllowedOrigin definition within master-config.yaml contains elements in the form ~~~ corsAllowedOrigins: - (?i)//my\.subdomain\.domain\.com(:|\z) ~~~ and not the form ~~~ corsAllowedOrigins: - domain.com ~~~ as the first will permit cross origin requests only if the host matches exactly, whereas the second will permit from any host that merely contains the string (such as ABCDdomain.com or even domain.comABCD.com). Footnotes: [1] https://docs.openshift.com/container-platform/3.4/architecture/infrastructure_components/web_console.html#corsAllowedOrigins
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.67% (0.00672) | 50.33th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.67% (0.00674) | 50.69th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.15% (0.00147) | 51.11th | v3 (v2023.03.01) |
| Mar 25, 2024 | 0.15% (0.00147) | 49.67th | v3 (v2023.03.01) |
| Feb 5, 2024 | 0.11% (0.00107) | 43.16th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.15% (0.00152) | 50.76th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00201) | 56.13th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Mar 31, 2022 | 3.28% (0.03283) | 66.48th | v2 (v2022.01.01) |
| Jan 6, 2022 | 3.63% (0.03630) | 71.48th | v1 |
| Jan 5, 2022 | 0.83% (0.00833) | 58.90th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (7)
- http://www.securityfocus.com/bid/107664 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1851 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3876 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1691107 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3876 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-3876
- https://www.cve.org/CVERecord?id=CVE-2019-3876
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/107664 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2019:1851 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-3876 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1691107 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3876 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-3876 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-3876 |
Change history (0)
No recorded changes yet.