CVE-2019-3889: Red Hat Openshift Container Platform

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.

Affected products

  • Red Hat Openshift Container Platform: from 3.4, up to and including 3.7; from 3.9, up to and including 3.11; version 4.1 only; version 4.2 only

Published 2019-07-11. Last modified 2026-06-17.