Lucene search

K
osvGoogleOSV:CVE-2019-3876
HistoryApr 01, 2019 - 3:29 p.m.

CVE-2019-3876

2019-04-0115:29:01
Google
osv.dev
4

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

50.8%

A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

50.8%