Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat OpenShift Enterprise 访问控制错误漏洞
Vulnerability Description
Red Hat OpenShift Enterprise是美国红帽(Red Hat)公司的一款企业版平台即服务(PaaS)云计算平台,它支持构建、测试、部署和运行应用程序。 Red Hat OpenShift Enterprise 3.2版本和3.1版本存在访问控制错误漏洞,该漏洞源于未正确验证请求的来源。远程攻击者利用该漏洞可以访问浏览器的本地存储中的API。
CVSS Information
N/A
Vulnerability Type
N/A