CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access inf...Show more |
1Redhat 7Jboss Enterprise Application Platform Jboss Enterprise Application Platform Text Only AdvisoriesOpenshift Container Platform+4 moreJun 17, 2026 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If th...Show more |
2Kubernetes Redhat2Kube Apiserver Openshift Container PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource b...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Ibm ZOpenshift Container Platform For Linuxone+2 moreJun 17, 2026 Sep 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code...Show more |
1Redhat 6Keycloak Openshift Container PlatformOpenshift Container Platform For Linuxone+3 moreJun 17, 2026 Sep 20, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more |
2Quarkus Redhat12Build Of Optaplanner Build Of QuarkusDecision Manager+9 moreJun 17, 2026 Sep 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an at...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Sep 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing t...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreJun 17, 2026 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Aug 4, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use th...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Jul 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by sett...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Arm64Openshift Container Platform For Linuxone+2 moreJun 17, 2026 Jul 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated. |
1Redhat 3Openshift Api For Data Protection Openshift Container PlatformOpenshift Developer Tools And ServicesJun 17, 2026 Jun 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to...Show more |
3Cloudbase DebianRedhat6Debian Linux Fast DatapathOpen Vswitch+3 moreJun 17, 2026 Apr 10, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapa...Show more |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Mar 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users...Show more |
1Redhat 2Openshift Assisted Installer Openshift Container PlatformJun 17, 2026 Mar 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-usin...Show more |
3Fedoraproject HaproxyRedhat9Ceph Storage Extra Packages For Enterprise LinuxFedora+6 moreJun 17, 2026 Mar 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenSh...Show more |
3Debian LinuxfoundationRedhat4Debian Linux Enterprise LinuxOpenshift Container Platform+1 moreJun 17, 2026 Mar 3, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount con...Show more |
1Redhat 2Openshift Container Platform Openshift OsinJun 17, 2026 Dec 28, 2022 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing disc...Show more |
2Buildah Project Redhat3Buildah Enterprise LinuxOpenshift Container PlatformJun 17, 2026 Sep 13, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected containe...Show more |
2Podman Project Redhat3Enterprise Linux Openshift Container PlatformPodmanJun 17, 2026 Sep 13, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container...Show more |