Bug 1767665 (CVE-2020-10715)

Summary: CVE-2020-10715 openshift/console: text injection on error page via crafted url
Product: [Other] Security Response Reporter: Mark Cooper <mcooper>
Component: vulnerabilityAssignee: Robb Hamilton <rhamilto>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: aos-bugs, bmontgom, eparis, jburrell, jhadvig, jokerman, nstielau, rhamilto, security-response-team, spadgett, sponnaga, wsun, xiaocwan, xiyuan, yapei
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: openshift/origin-web-console 2ff65968d1b23ac70aee0bb7c4aa5366378f8ee6 Doc Type: If docs needed, set a value
Doc Text:
A content spoofing vulnerability was found in the openshift/console. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-07-27 19:27:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1827004, 1827005    
Bug Blocks: 1767666    

Description Mark Cooper 2019-10-31 23:35:20 UTC
In the OpenShift web console in versions 3.11 and 4.x an attacker can craft a URL in which to inject arbitrary text into error pages. This could be used to convince a user that the injected text is legitimate. 

References:

https://www.owasp.org/index.php/Content_Spoofing

Comment 6 Mark Cooper 2020-04-23 02:26:43 UTC
As pointed out by spadgett, this issue also affects OpenShift 4.x:
    - https://github.com/spadgett/console/blob/d390194f13bab8175e42eaf5a077a220b538624f/frontend/public/components/error.tsx#L33-L44

Comment 10 errata-xmlrpc 2020-07-27 18:49:24 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 3.11

Via RHSA-2020:2992 https://access.redhat.com/errata/RHSA-2020:2992

Comment 11 Product Security DevOps Team 2020-07-27 19:27:40 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-10715

Comment 12 Mark Cooper 2020-07-29 05:20:30 UTC
Upstream fix: https://github.com/openshift/origin-web-console/pull/3173

Comment 13 errata-xmlrpc 2020-10-27 16:23:43 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.6

Via RHSA-2020:4298 https://access.redhat.com/errata/RHSA-2020:4298