CVE-2018-10937

Source
https://cve.org/CVERecord?id=CVE-2018-10937
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10937.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-10937
Published
2018-09-11T16:29:00.230Z
Modified
2026-07-08T15:54:32.771769Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.

References

Affected packages

Git / github.com/openshift/console

Affected ranges

Type
GIT
Repo
https://github.com/openshift/console
Events
Database specific
{
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.11"
        },
        {
            "last_affected": "3.11"
        }
    ]
}

Affected versions

3.*
3.11
v3.*
v3.11.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-10937.json"