5.4

CVE-2017-7534

OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.

Data is provided by the National Vulnerability Database (NVD)
RedhatOpenshift Version3.0 SwEditionenterprise
RedhatOpenshift Version3.1 SwEditionenterprise
RedhatOpenshift Version3.2 SwEditionenterprise
RedhatOpenshift Version3.3 SwEditionenterprise
RedhatOpenshift Version3.4 SwEditionenterprise
RedhatOpenshift Version3.5 SwEditionenterprise
RedhatOpenshift Version3.6 SwEditionenterprise
RedhatOpenshift Version3.7 SwEditionenterprise
RedhatOpenshift Version3.9 SwEditionenterprise
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.346
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.3 2.7
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.