Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the get_oauth_token method of osbs-client. An attacker with local access to the osbs-client logs could use this flaw to steal the access token for OpenShift OSBS workers.
Acknowledgments: Name: Martin Basti (Red Hat)
Created osbs-client tracking bugs for this issue: Affects: epel-all [bug 1697218] Affects: fedora-all [bug 1697217]