Skip to main content

Insufficient Entropy

CVE-2024-6508

Severity High
Score 8/10

Summary

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the "state" parameter is used inefficiently. This flaw allows logging into the victim's current application account using a third-party account without any restrictions.

  • HIGH
  • NETWORK
  • HIGH
  • CHANGED
  • REQUIRED
  • LOW
  • HIGH
  • HIGH

CWE-331 - Insufficient Entropy

The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Advisory Timeline

  • Published