CVE-2024-6508
Openshift-console: oauth2 insufficient state parameter entropy
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Productos afectados
openshift-consoleRed Hat · Red Hat OpenShift Container Platform 4.12Red Hat · Red Hat OpenShift Container Platform 4.13Red Hat · Red Hat OpenShift Container Platform 4.14Red Hat · Red Hat OpenShift Container Platform 4.15Red Hat · Red Hat OpenShift Container Platform 4.16Red Hat · Red Hat OpenShift Container Platform 4.17¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2024:10813https://access.redhat.com/errata/RHSA-2024:7922https://access.redhat.com/errata/RHSA-2024:8415https://access.redhat.com/errata/RHSA-2024:8991https://access.redhat.com/errata/RHSA-2024:9620https://access.redhat.com/errata/RHSA-2025:0014https://access.redhat.com/security/cve/CVE-2024-6508https://bugzilla.redhat.com/show_bug.cgi?id=2295777