{"id":"GHSA-4crf-28c7-v4gr","summary":"Openshift Console insufficient entropy vulnerability","details":"An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.","aliases":["CVE-2024-6508","GO-2024-3083"],"modified":"2025-01-09T09:31:40Z","published":"2024-08-21T06:32:18Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-08-21T20:09:39Z","nvd_published_at":"2024-08-21T06:15:08Z","cwe_ids":["CWE-331"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-6508"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:10813"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:7922"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8415"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:8991"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2024:9620"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2025:0014"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2024-6508"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2295777"},{"type":"PACKAGE","url":"https://github.com/openshift/console"}],"affected":[{"package":{"name":"github.com/openshift/console","ecosystem":"Go","purl":"pkg:golang/github.com/openshift/console"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"6.0.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-4crf-28c7-v4gr/GHSA-4crf-28c7-v4gr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H"}]}