Podatność CVE-2024-6508


Publikacja: 2024-08-21

Opis:
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim??s current application account using a third-party account without any restrictions.

Typ:

CWE-331

(Insufficient Entropy)

 Referencje:
https://access.redhat.com/security/cve/CVE-2024-6508
https://bugzilla.redhat.com/show_bug.cgi?id=2295777

Copyright 2024, cxsecurity.com

 

Back to Top