CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian HaproxyRedhat5Debian Linux Enterprise LinuxHaproxy+2 moreJun 17, 2026 Mar 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulti...Show more |
4Canonical DebianPolkit Project+1 more6Debian Linux Openshift Container PlatformPolkit+3 moreJun 17, 2026 Feb 16, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to,...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Feb 9, 2022 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
1Redhat 2Noobaa Operator Openshift Container PlatformJun 17, 2026 Jun 2, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The inp...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Plat...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Jun 2, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into p...Show more |
3Fedoraproject GnomeRedhat4Enterprise Linux FedoraNetworkmanager+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability. |
1Redhat 1Openshift Container Platform Jun 17, 2026 May 14, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerabi...Show more |
3Fedoraproject RedhatStorage Project4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Apr 1, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archiv...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Mar 24, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/pas...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Mar 24, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passw...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Mar 24, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/pas...Show more |
4Debian FedoraprojectPygments+1 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "except...Show more |
1Redhat 2Openshift Openshift Container PlatformJun 17, 2026 Mar 19, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Mar 19, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, ru...Show more |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
1Redhat 2Openshift Builder Openshift Container PlatformJun 17, 2026 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execu...Show more |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreJun 17, 2026 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |
3Fedoraproject LinuxRedhat5Enterprise Linux FedoraLinux Kernel+2 moreJun 17, 2026 Mar 4, 2021 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local use...Show more |