VDB
RHSA-2024%3A9620
RHSA-2024%3A9620
PUBLISHED
CVSS 8 HIGH
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/driver-toolkit-rhel9@sha256:3ea4f547d09661792698c845408d1f6facfa35bbb202cffa5c63b6f62a912b19_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/driver-toolkit-rhel9@sha256:3ea4f547d09661792698c845408d1f6facfa35bbb202cffa5c63b6f62a912b19_amd64 |
| Red Hat | openshift4/ose-must-gather@sha256:2bb6cfb470bdebfe0d1c5fec00ed5d2242b7ed252eb8b39363f88be72bf4c9f8_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-must-gather@sha256:2bb6cfb470bdebfe0d1c5fec00ed5d2242b7ed252eb8b39363f88be72bf4c9f8_s390x |
| Red Hat | openshift4/ose-installer-artifacts@sha256:b160df9dacf56a63d13cdf17b2978b0b0f557714cf45719205ad23029e410fee_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-installer-artifacts@sha256:b160df9dacf56a63d13cdf17b2978b0b0f557714cf45719205ad23029e410fee_ppc64le |
| Red Hat | openshift4/ose-hypershift-rhel8@sha256:dceac7b6e8215584699ddedff3932119d9df1a23f97a49a37efcae89c01cba4c_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-hypershift-rhel8@sha256:dceac7b6e8215584699ddedff3932119d9df1a23f97a49a37efcae89c01cba4c_arm64 |
| Red Hat | openshift4/ose-csi-snapshot-controller-rhel8@sha256:43f882b5eab0d550ec94402eb2698f21e3bec7b51d6cd769d20b6ddc6a4a72d2_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-csi-snapshot-controller-rhel8@sha256:43f882b5eab0d550ec94402eb2698f21e3bec7b51d6cd769d20b6ddc6a4a72d2_s390x |
| Red Hat | openshift4/ose-cluster-ingress-operator@sha256:c82f328315bd5d15bc820a777ea9ce42fda30f445a640c167e0b3077f533cd20_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-cluster-ingress-operator@sha256:c82f328315bd5d15bc820a777ea9ce42fda30f445a640c167e0b3077f533cd20_s390x |
| Red Hat | openshift4/ose-csi-node-driver-registrar-rhel8@sha256:4f4c4595115fd086f18ad23b9a0f07a73cd15800f45b01aa4ad782bfffe6742b_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-csi-node-driver-registrar-rhel8@sha256:4f4c4595115fd086f18ad23b9a0f07a73cd15800f45b01aa4ad782bfffe6742b_arm64 |
| Red Hat | openshift4/ose-tools-rhel8@sha256:88d76ab358deb5a43001ca1753f349e0648435d1b608407eafc3c4402cac0fc9_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-tools-rhel8@sha256:88d76ab358deb5a43001ca1753f349e0648435d1b608407eafc3c4402cac0fc9_ppc64le |
| Red Hat | openshift4/ose-multus-cni@sha256:9049b4750e7c3a61cb66da325cd5d319195cb287473d9981e5de06cee2308f74_s390x as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-multus-cni@sha256:9049b4750e7c3a61cb66da325cd5d319195cb287473d9981e5de06cee2308f74_s390x |
| Red Hat | openshift4/ose-cluster-olm-operator-rhel8@sha256:202448d9b023d4d0bc95d24518d573484f8090fd5d4ab22b63f082eba85a1677_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-cluster-olm-operator-rhel8@sha256:202448d9b023d4d0bc95d24518d573484f8090fd5d4ab22b63f082eba85a1677_ppc64le |
| Red Hat | openshift4/ose-baremetal-rhel8-operator@sha256:e1589037974abfd4afc0190b5f6ccac4e70e49c0fb0e9f072730c0cf6c8cdf59_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-baremetal-rhel8-operator@sha256:e1589037974abfd4afc0190b5f6ccac4e70e49c0fb0e9f072730c0cf6c8cdf59_amd64 |
| Red Hat | openshift4/ose-cluster-capi-operator-container-rhel8@sha256:a049d4eabe247e5cab151a8a41af1fc7c1ffe38216a4da6eb10cddaafb1d9cd1_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-cluster-capi-operator-container-rhel8@sha256:a049d4eabe247e5cab151a8a41af1fc7c1ffe38216a4da6eb10cddaafb1d9cd1_arm64 |
| Red Hat | openshift4/ose-cluster-network-operator@sha256:5c57c3e24ec6bed29d191c447d8828e6d772750de8e271dac4e054f04763ea96_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-cluster-network-operator@sha256:5c57c3e24ec6bed29d191c447d8828e6d772750de8e271dac4e054f04763ea96_arm64 |
| Red Hat | openshift4/ose-kube-proxy@sha256:80427efc04334acccbe52ef38197779019a4cf9775c378fc70dfbf3f516a3a46_amd64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-kube-proxy@sha256:80427efc04334acccbe52ef38197779019a4cf9775c378fc70dfbf3f516a3a46_amd64 |
| Red Hat | openshift4/ose-csi-external-provisioner@sha256:f731e248fb0bf4a16cd80739d2601204693933de0869a2867631409beb713f6d_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-csi-external-provisioner@sha256:f731e248fb0bf4a16cd80739d2601204693933de0869a2867631409beb713f6d_arm64 |
| Red Hat | openshift4/ose-cluster-autoscaler-operator@sha256:887b88fb07805a3f27b2854d9bb5474fae8b8d5eaf6f01f24cf80672147ddfa4_s390x as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/cloud-network-config-controller-rhel8@sha256:df5267606dc4a04ef36dd1941eb66703f21e2ee3fff16a597fb9fefe50b96cfc_arm64 as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-cluster-autoscaler-operator@sha256:c7ec9a1f7e0f7c565fe95e837ab7b7af4969e289b83e1c5eb0cf8960415d029e_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | * |
| Red Hat | openshift4/ose-cluster-machine-approver@sha256:a630a9c09c789c8895dfab1c958c0bc2a593253279ad6bb78722a75fc6d1f5aa_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-cluster-machine-approver@sha256:a630a9c09c789c8895dfab1c958c0bc2a593253279ad6bb78722a75fc6d1f5aa_ppc64le |
| Red Hat | openshift4/ose-operator-marketplace@sha256:043fabed73558359ce05314145e90af72b4ba5b08ee1e7eb774ba197c6363970_ppc64le as a component of Red Hat OpenShift Container Platform 4.14 | openshift4/ose-operator-marketplace@sha256:043fabed73558359ce05314145e90af72b4ba5b08ee1e7eb774ba197c6363970_ppc64le |
…and 647 more
Timeline
- Nov 20, 2024 CVE Published
- Apr 30, 2026 CVE Updated
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Distribution Patch
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
- Apr 30, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2024:9620 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2295777 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2302487 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2318052 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2322949 issue
- https://issues.redhat.com/browse/OCPBUGS-42111 advisory
- https://issues.redhat.com/browse/OCPBUGS-43490 advisory
- https://issues.redhat.com/browse/OCPBUGS-43647 advisory
- https://issues.redhat.com/browse/OCPBUGS-43980 advisory
- https://issues.redhat.com/browse/OCPBUGS-43981 advisory
- https://issues.redhat.com/browse/OCPBUGS-44002 advisory
- https://issues.redhat.com/browse/OCPBUGS-44048 advisory
- https://issues.redhat.com/browse/OCPBUGS-44095 advisory
- https://issues.redhat.com/browse/OCPBUGS-44107 advisory
- https://issues.redhat.com/browse/OCPBUGS-44213 advisory
- https://issues.redhat.com/browse/OCPBUGS-44295 advisory
- https://issues.redhat.com/browse/OCPBUGS-44304 advisory
- https://issues.redhat.com/browse/OCPBUGS-44360 advisory
- https://issues.redhat.com/browse/OCPBUGS-44379 advisory
…and 19 more