CVE-2017-7534
Last modified
CVE-2017-7534 is a vulnerability of currently unknown severity. OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.0 |
| Redhat | Openshift | 3.1 |
| Redhat | Openshift | 3.2 |
| Redhat | Openshift | 3.3 |
| Redhat | Openshift | 3.4 |
| Redhat | Openshift | 3.5 |
| Redhat | Openshift | 3.6 |
| Redhat | Openshift | 3.7 |
| Redhat | Openshift | 3.9 |
References
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7534?
How severe is CVE-2017-7534?
How do I fix CVE-2017-7534?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7528Ansible Tower as shipped with Red Hat CloudForms Management …5.2
- CVE-2017-7529Nginx versions since 0.5.6 up to and including 1.13.2 are vu…7.5
- CVE-2017-7530In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.…8.8
- CVE-2017-7531In Moodle 3.3, the course overview block reveals activities …
- CVE-2017-7532In Moodle 3.x, course creators are able to change system def…
- CVE-2017-7533Race condition in the fsnotify implementation in the Linux k…7
- CVE-2017-7535foreman before version 1.16.0 is vulnerable to a stored XSS …6.1
- CVE-2017-7536In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and …7
- CVE-2017-7537It was found that a mock CMC authentication plugin with a ha…5.9
- CVE-2017-7538A cross-site scripting (XSS) flaw was found in how an organi…3.5
- CVE-2017-7539An assertion-failure flaw was found in Qemu before 2.10.1, i…5.3
- CVE-2017-7540rubygem-safemode, as used in Foreman, versions 1.3.2 and ear…
Are you affected by CVE-2017-7534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
