Vulnerability Details CVE-2019-3889
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 56.8%
CVSS Severity
CVSS v3 Score 4.6
CVSS v2 Score 3.5
Products affected by CVE-2019-3889
-
cpe:2.3:a:redhat:openshift_container_platform:3.10
-
cpe:2.3:a:redhat:openshift_container_platform:3.11
-
cpe:2.3:a:redhat:openshift_container_platform:3.4
-
cpe:2.3:a:redhat:openshift_container_platform:3.5
-
cpe:2.3:a:redhat:openshift_container_platform:3.6
-
cpe:2.3:a:redhat:openshift_container_platform:3.7
-
cpe:2.3:a:redhat:openshift_container_platform:3.9
-
cpe:2.3:a:redhat:openshift_container_platform:3.9.31
-
cpe:2.3:a:redhat:openshift_container_platform:4.1
-
cpe:2.3:a:redhat:openshift_container_platform:4.2