Red Hat Bugzilla – Bug 1622372
CVE-2018-10937 tectonic-console: XSS Vulnerability in K8s API proxy
Last modified: 2018-08-28 01:58:29 EDT
A XSS flaw exists in the tetonic-console component of Openshift Container Platfrom 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
Acknowledgments: Name: Sam Padgett (Red Hat)
References: https://github.com/openshift/console/pull/461 Upstream fix: https://github.com/openshift/console/commit/d56666852da6e7309a2e63a49f49a72ff66d309c