VDB

RHSA-2024%3A9620

RHSA-2024%3A9620 PUBLISHED CVSS 8 HIGH

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

Risk Scores

CVSS 3.1
8
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red Hatopenshift4/driver-toolkit-rhel9@sha256:3ea4f547d09661792698c845408d1f6facfa35bbb202cffa5c63b6f62a912b19_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/driver-toolkit-rhel9@sha256:3ea4f547d09661792698c845408d1f6facfa35bbb202cffa5c63b6f62a912b19_amd64
Red Hatopenshift4/ose-must-gather@sha256:2bb6cfb470bdebfe0d1c5fec00ed5d2242b7ed252eb8b39363f88be72bf4c9f8_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-must-gather@sha256:2bb6cfb470bdebfe0d1c5fec00ed5d2242b7ed252eb8b39363f88be72bf4c9f8_s390x
Red Hatopenshift4/ose-installer-artifacts@sha256:b160df9dacf56a63d13cdf17b2978b0b0f557714cf45719205ad23029e410fee_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-installer-artifacts@sha256:b160df9dacf56a63d13cdf17b2978b0b0f557714cf45719205ad23029e410fee_ppc64le
Red Hatopenshift4/ose-hypershift-rhel8@sha256:dceac7b6e8215584699ddedff3932119d9df1a23f97a49a37efcae89c01cba4c_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-hypershift-rhel8@sha256:dceac7b6e8215584699ddedff3932119d9df1a23f97a49a37efcae89c01cba4c_arm64
Red Hatopenshift4/ose-csi-snapshot-controller-rhel8@sha256:43f882b5eab0d550ec94402eb2698f21e3bec7b51d6cd769d20b6ddc6a4a72d2_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-csi-snapshot-controller-rhel8@sha256:43f882b5eab0d550ec94402eb2698f21e3bec7b51d6cd769d20b6ddc6a4a72d2_s390x
Red Hatopenshift4/ose-cluster-ingress-operator@sha256:c82f328315bd5d15bc820a777ea9ce42fda30f445a640c167e0b3077f533cd20_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-ingress-operator@sha256:c82f328315bd5d15bc820a777ea9ce42fda30f445a640c167e0b3077f533cd20_s390x
Red Hatopenshift4/ose-csi-node-driver-registrar-rhel8@sha256:4f4c4595115fd086f18ad23b9a0f07a73cd15800f45b01aa4ad782bfffe6742b_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-csi-node-driver-registrar-rhel8@sha256:4f4c4595115fd086f18ad23b9a0f07a73cd15800f45b01aa4ad782bfffe6742b_arm64
Red Hatopenshift4/ose-tools-rhel8@sha256:88d76ab358deb5a43001ca1753f349e0648435d1b608407eafc3c4402cac0fc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-tools-rhel8@sha256:88d76ab358deb5a43001ca1753f349e0648435d1b608407eafc3c4402cac0fc9_ppc64le
Red Hatopenshift4/ose-multus-cni@sha256:9049b4750e7c3a61cb66da325cd5d319195cb287473d9981e5de06cee2308f74_s390x as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-multus-cni@sha256:9049b4750e7c3a61cb66da325cd5d319195cb287473d9981e5de06cee2308f74_s390x
Red Hatopenshift4/ose-cluster-olm-operator-rhel8@sha256:202448d9b023d4d0bc95d24518d573484f8090fd5d4ab22b63f082eba85a1677_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-olm-operator-rhel8@sha256:202448d9b023d4d0bc95d24518d573484f8090fd5d4ab22b63f082eba85a1677_ppc64le
Red Hatopenshift4/ose-baremetal-rhel8-operator@sha256:e1589037974abfd4afc0190b5f6ccac4e70e49c0fb0e9f072730c0cf6c8cdf59_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-baremetal-rhel8-operator@sha256:e1589037974abfd4afc0190b5f6ccac4e70e49c0fb0e9f072730c0cf6c8cdf59_amd64
Red Hatopenshift4/ose-cluster-capi-operator-container-rhel8@sha256:a049d4eabe247e5cab151a8a41af1fc7c1ffe38216a4da6eb10cddaafb1d9cd1_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-capi-operator-container-rhel8@sha256:a049d4eabe247e5cab151a8a41af1fc7c1ffe38216a4da6eb10cddaafb1d9cd1_arm64
Red Hatopenshift4/ose-cluster-network-operator@sha256:5c57c3e24ec6bed29d191c447d8828e6d772750de8e271dac4e054f04763ea96_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-network-operator@sha256:5c57c3e24ec6bed29d191c447d8828e6d772750de8e271dac4e054f04763ea96_arm64
Red Hatopenshift4/ose-kube-proxy@sha256:80427efc04334acccbe52ef38197779019a4cf9775c378fc70dfbf3f516a3a46_amd64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-kube-proxy@sha256:80427efc04334acccbe52ef38197779019a4cf9775c378fc70dfbf3f516a3a46_amd64
Red Hatopenshift4/ose-csi-external-provisioner@sha256:f731e248fb0bf4a16cd80739d2601204693933de0869a2867631409beb713f6d_arm64 as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-csi-external-provisioner@sha256:f731e248fb0bf4a16cd80739d2601204693933de0869a2867631409beb713f6d_arm64
Red Hatopenshift4/ose-cluster-autoscaler-operator@sha256:887b88fb07805a3f27b2854d9bb5474fae8b8d5eaf6f01f24cf80672147ddfa4_s390x as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/cloud-network-config-controller-rhel8@sha256:df5267606dc4a04ef36dd1941eb66703f21e2ee3fff16a597fb9fefe50b96cfc_arm64 as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-cluster-autoscaler-operator@sha256:c7ec9a1f7e0f7c565fe95e837ab7b7af4969e289b83e1c5eb0cf8960415d029e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14*
Red Hatopenshift4/ose-cluster-machine-approver@sha256:a630a9c09c789c8895dfab1c958c0bc2a593253279ad6bb78722a75fc6d1f5aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-cluster-machine-approver@sha256:a630a9c09c789c8895dfab1c958c0bc2a593253279ad6bb78722a75fc6d1f5aa_ppc64le
Red Hatopenshift4/ose-operator-marketplace@sha256:043fabed73558359ce05314145e90af72b4ba5b08ee1e7eb774ba197c6363970_ppc64le as a component of Red Hat OpenShift Container Platform 4.14openshift4/ose-operator-marketplace@sha256:043fabed73558359ce05314145e90af72b4ba5b08ee1e7eb774ba197c6363970_ppc64le

…and 647 more

Timeline

  • Nov 20, 2024 CVE Published
  • Apr 30, 2026 CVE Updated
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Distribution Patch
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
  • Apr 30, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›