CVE-2018-10937

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
11/09/2018
Last modified:
09/10/2019

Description

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*