Withdrawn Advisory: OpenShift OAuth Server XSS Vulnerability
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Sep 28, 2023
Withdrawn
This advisory was withdrawn on Sep 28, 2023
Package
Affected versions
>= 3.0, < 3.11
Patched versions
3.11
Description
Published by the National Vulnerability Database
Apr 1, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jul 19, 2023
Withdrawn
Sep 28, 2023
Last updated
Sep 28, 2023
Withdrawn Advisory
This advisory has been withdrawn because the vulnerability does not affect a package in one of the GitHub Advisory Database's supported ecosystems. This link is maintained to preserve external references.
Original Description
A flaw was found in the
/oauth/token/request
custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.References