A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the users browser and the openshift console, could use this flaw to perform a phishing attack. The main threat from this vulnerability is data confidentiality.
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openshift_container_platform | Redhat | 3.11 (including) | 3.11 (including) |
Red Hat OpenShift Container Platform 3.11 | RedHat | openshift-ansible-0:3.11.272-1.git.0.79ab6e9.el7 | * |