CVE-2019-3889: Red Hat Openshift Container Platform
Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
Affected products
- Red Hat Openshift Container Platform: from 3.4, up to and including 3.7; from 3.9, up to and including 3.11; version 4.1 only; version 4.2 only
Published 2019-07-11. Last modified 2026-06-17.