CVE-2019-10176: Red Hat Openshift Container Platform

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.

Affected products

  • Red Hat Openshift Container Platform: version 3.11 only; version 4.1 only

Published 2019-08-02. Last modified 2026-06-17.