← Back to CVE List

CVE-2024-6508

Published: 2024-08-21T06:15Z
Last Modified: 2025-01-09T09:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt