OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: redhat
Published: 2018-04-11T19:00:00Z
Updated: 2024-08-05T16:04:11.828Z
Reserved: 2017-04-05T00:00:00
Link: CVE-2017-7534

No data.

Status : Modified
Published: 2018-04-11T19:29:00.213
Modified: 2024-11-21T03:32:06.147
Link: CVE-2017-7534
