Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-27816
HistoryDec 02, 2020 - 1:15 a.m.

Design/Logic Flaw

2020-12-0201:15:00
PRIOn knowledge base
www.prio-n.com
3

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.8%

The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging console link damage. This flaw affects elasticsearch-operator-container versions before 4.7.

6.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

33.8%

Related for PRION:CVE-2020-27816