Content spoofing
Published Oct 5, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.60%
Description
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
Affected products
-
- Vendor n/a Product Openshift Defaultaffected
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4 | affected |
| |||
| n/a | Openshift | affected |
|
- 4.0
No data.
Red Hat OpenShift Container Platform 4
openshift
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | openshift | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This has been rated as low impact as there is no exploitability for this vulnerability, the vulnerability is a content injection in the error message that comes back as json data, an attacker cannot use this in any meaningful way to attack a victim, on top of that this attack would require user interaction of the victim to click the crafted URL, all of these points to this being not exploitable in any meaningful way.
References (4)
- https://access.redhat.com/security/cve/CVE-2022-4145 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2148667 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4145
- https://www.cve.org/CVERecord?id=CVE-2022-4145
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-4145 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2148667 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4145 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-4145 |
Change history (0)
No recorded changes yet.