CVE-2017-7534
Last modified
CVE-2017-7534 is a vulnerability of currently unknown severity. OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openshift | 3.0 |
| Redhat | Openshift | 3.1 |
| Redhat | Openshift | 3.2 |
| Redhat | Openshift | 3.3 |
| Redhat | Openshift | 3.4 |
| Redhat | Openshift | 3.5 |
| Redhat | Openshift | 3.6 |
| Redhat | Openshift | 3.7 |
| Redhat | Openshift | 3.9 |
References
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
- http://www.securityfocus.com/bid/103754Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1443003Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7534?
How severe is CVE-2017-7534?
How do I fix CVE-2017-7534?
Are you affected by CVE-2017-7534?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
