Description


A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.

Related CPE's


References



Weaknesses



CWE-358


NVD-CWE-Other

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.1 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-05-27T18:15:08.030Z

4 years ago

Last modified

2024-11-21T04:11:19.867Z

1 year ago