An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
References
Configurations
No configuration.
History
09 Jan 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Dec 2024, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-08-21 06:15
Updated : 2025-01-09 09:15
NVD link : CVE-2024-6508
Mitre link : CVE-2024-6508
CVE.ORG link : CVE-2024-6508
JSON object : View
Products Affected
No product.
CWE
CWE-331
Insufficient Entropy