Insufficient Entropy
CVE-2024-6508
Summary
An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the "state" parameter is used inefficiently. This flaw allows logging into the victim's current application account using a third-party account without any restrictions.
- HIGH
- NETWORK
- HIGH
- CHANGED
- REQUIRED
- LOW
- HIGH
- HIGH
CWE-331 - Insufficient Entropy
The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Advisory Timeline
- Published