Releases142
Frequency1 week 3 hours
Last Release
Stars456
OpenShift Cluster Console UI

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's GraphQL implementation.

3.5 LOW

A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.