CVE-2017-7534

Source
https://cve.org/CVERecord?id=CVE-2017-7534
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7534.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7534
Published
2018-04-11T19:29:00.213Z
Modified
2026-07-08T05:50:29.555266449Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "3.0"
                },
                {
                    "last_affected": "3.0"
                },
                {
                    "introduced": "3.1"
                },
                {
                    "last_affected": "3.1"
                },
                {
                    "introduced": "3.2"
                },
                {
                    "last_affected": "3.2"
                },
                {
                    "introduced": "3.3"
                },
                {
                    "last_affected": "3.3"
                },
                {
                    "introduced": "3.4"
                },
                {
                    "last_affected": "3.4"
                },
                {
                    "introduced": "3.5"
                },
                {
                    "last_affected": "3.5"
                }
            ],
            "cpes": [
                "cpe:2.3:a:redhat:openshift:3.0:*:*:*:enterprise:*:*:*",
                "cpe:2.3:a:redhat:openshift:3.1:*:*:*:enterprise:*:*:*",
                "cpe:2.3:a:redhat:openshift:3.2:*:*:*:enterprise:*:*:*",
                "cpe:2.3:a:redhat:openshift:3.3:*:*:*:enterprise:*:*:*",
                "cpe:2.3:a:redhat:openshift:3.4:*:*:*:enterprise:*:*:*",
                "cpe:2.3:a:redhat:openshift:3.5:*:*:*:enterprise:*:*:*"
            ],
            "source": "CPE_STRING",
            "vendor_product": "redhat:openshift"
        }
    ]
}
References

Affected packages

Git / github.com/openshift/origin

Affected ranges

Type
GIT
Repo
https://github.com/openshift/origin
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.6"
        },
        {
            "last_affected": "3.6"
        },
        {
            "introduced": "3.7"
        },
        {
            "last_affected": "3.7"
        },
        {
            "introduced": "3.9"
        },
        {
            "last_affected": "3.9"
        }
    ],
    "cpe": [
        "cpe:2.3:a:redhat:openshift:3.6:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:redhat:openshift:3.7:*:*:*:enterprise:*:*:*",
        "cpe:2.3:a:redhat:openshift:3.9:*:*:*:enterprise:*:*:*"
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.6
3.7
3.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7534.json"