A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-27T19:45:14

Updated: 2024-08-04T06:46:30.893Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2020-1761

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-27T20:15:08.030

Modified: 2024-11-21T05:11:19.867

Link: CVE-2020-1761

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-02-11T00:00:00Z

Links: CVE-2020-1761 - Bugzilla