LWN.net Logo

openshift-console: code execution

Package(s):openshift-console CVE #(s):CVE-2012-5622
Created:December 11, 2012 Updated:December 12, 2012
Description: From the Red Hat advisory:

It was found that the OpenShift Management Console did not protect against Cross-Site Request Forgery (CSRF) attacks. If a remote attacker could trick a user, who was logged into the OpenShift Management Console, into visiting an attacker controlled web page, the attacker could make changes to applications hosted within OpenShift Enterprise with the privileges of the victim which may lead to arbitrary code execution in the OpenShift Enterprise hosted applications.

Alerts:
Red Hat RHSA-2012:1555-01 2012-12-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds