CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat3Enterprise Linux Linux KernelOpenshift Container PlatformJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Feb 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container,...Show more |
2Podman Project Redhat3Enterprise Linux Openshift Container PlatformPodmanJun 17, 2026 Feb 11, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access an...Show more |
4Fedoraproject GrafanaRedhat+1 more6Enterprise Linux FedoraGrafana+3 moreJun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av...Show more |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
2Linux Redhat3Enterprise Linux Linux KernelOpenshift Container PlatformJun 17, 2026 Dec 15, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a...Show more |
3Linux NetappRedhat6Cloud Backup Enterprise LinuxEnterprise Mrg+3 moreJun 17, 2026 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this spec...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Dec 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one,...Show more |
2Heketi Project Redhat4Enterprise Linux Gluster StorageHeketi+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as g...Show more |
2Fedoraproject Redhat4Ceph Ceph StorageFedora+1 moreJun 17, 2026 Nov 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more |
3Fedoraproject Podman ProjectRedhat4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 5.3 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short dura...Show more |
8Canonical DebianGnu+5 more15Active Iq Unified Manager Debian LinuxEnterprise Linux+12 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |
2Docker Redhat3Docker Enterprise Linux ServerOpenshift Container PlatformJun 17, 2026 Jul 13, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304....Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary co...Show more |
3Fedoraproject LinuxfoundationRedhat4Cni Network Plugins Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container ca...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 May 12, 2020 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then u...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection bet...Show more |