{"id":"CVE-2019-3876","details":"A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.","modified":"2026-03-15T22:28:35.460459Z","published":"2019-04-01T15:29:01.123Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/107664"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1851"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3876"}],"affected":[{"database_specific":{"unresolved_ranges":[{"events":[{"introduced":"3.0"},{"last_affected":"3.11"}]}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3876.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}