GHSA-4crf-28c7-v4gr
GitHub Security Advisory
Openshift Console insufficient entropy vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
Affected Packages
Go
github.com/openshift/console
Affected versions:
0
(last affected: 6.0.6)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.