A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2022-4145 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2148667 | Issue Tracking Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-10-05 13:15
Updated : 2023-11-07 03:57
NVD link : CVE-2022-4145
Mitre link : CVE-2022-4145
CVE.ORG link : CVE-2022-4145
JSON object : View
Products Affected
redhat
- openshift_container_platform
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')