Back

MEDIUM

Content spoofing

Published Oct 5, 2023

Description

A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.

Affected products

Remediation

Red Hat statement

This has been rated as low impact as there is no exploitability for this vulnerability, the vulnerability is a content injection in the error message that comes back as json data, an attacker cannot use this in any meaningful way to attack a victim, on top of that this attack would require user interaction of the victim to click the crafted URL, all of these points to this being not exploitable in any meaningful way.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 5, 2023
Updated Sep 3, 2024
Reserved Nov 26, 2022
CISA Vulnrichment
Updated Sep 3, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 22, 2022