CVE-2024-6508
ADVISORY - githubSummary
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.
EPSS Score: 0.00673 (0.498)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Insufficient Entropy
ADVISORY - github
Insufficient Entropy
ADVISORY - gitlab
ADVISORY - redhat
Insufficient Entropy
NIST
CREATED
UPDATED
ADVISORY IDCVE-2024-6508
EXPLOITABILITY SCORE
1.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
8highGitHub
CREATED
UPDATED
ADVISORY IDGHSA-4crf-28c7-v4gr
EXPLOITABILITY SCORE
1.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.5mediumGoLang
CREATED
UPDATED
ADVISORY IDGO-2024-3083
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
Red Hat
CREATED
UPDATED
ADVISORY IDCVE-2024-6508
EXPLOITABILITY SCORE
1.3
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)