Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-38681

CVE-2023-29400: fix unquoted attributes in net/http templates

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Not a Bug
    • Icon: Critical Critical
    • None
    • 4.12.z
    • oauth-apiserver
    • None
    • None
    • 2
    • SDN Sprint 258
    • 1
    • False
    • Hide

      None

      Show
      None

      there is a match that should be addressed:

      1:File: pkg/server/tokenrequest/tokenrequest.go
      2:Match: token={{.AccessToken}}</span> <span class="nowrap">--server={{.PublicMasterURL}}
      

      both AccessToken and PublicMasterURL should be wrapped in quotes.

              jluhrsen Jamo Luhrsen
              jluhrsen Jamo Luhrsen
              Xingxing Xia Xingxing Xia
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: