← Back

Openshift Container Platform

openshift_container_platform

Vendor: Redhat • 326 CVEs

CVEs (326)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Elastic
Redhat
2Kibana
Openshift Container Platform
Jun 17, 2026
Dec 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one,...Show more
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging console link damage. This flaw affects elasticsearch-operator-container versions before 4.7.Show less
2Heketi Project
Redhat
4Enterprise Linux
Gluster StorageHeketi+1 more
Jun 17, 2026
Nov 24, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as g...Show more
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.Show less
2Fedoraproject
Redhat
4Ceph
Ceph StorageFedora+1 more
Jun 17, 2026
Nov 23, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.Show less
3Fedoraproject
Podman ProjectRedhat
4Enterprise Linux
FedoraOpenshift Container Platform+1 more
Jun 17, 2026
Sep 23, 2020
N/A· v4
5.3 MEDIUM· v3
4.0 MEDIUM· v2
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short dura...Show more
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control over the subsequent containers could use this flaw to gain access to sensitive information stored in such variables.Show less
8Canonical
DebianGnu+5 more
15Active Iq Unified Manager
Debian LinuxEnterprise Linux+12 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command on 32-bit architectures, or a crafted filesystem with very large files on any architecture. An attacker could use this to execute arbitrary code and bypass UEFI Secure Boot restrictions. This issue affects GRUB2 version 2.04 and prior versions.Show less
7Canonical
DebianGnu+4 more
14Debian Linux
Enterprise LinuxEnterprise Linux Atomic Host+11 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.Show less
7Canonical
DebianGnu+4 more
14Debian Linux
Enterprise LinuxEnterprise Linux Atomic Host+11 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
6.4 MEDIUM· v3
4.4 MEDIUM· v2
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions.Show less
2Docker
Redhat
3Docker
Enterprise Linux ServerOpenshift Container Platform
Jun 17, 2026
Jul 13, 2020
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304....Show more
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and other containers running on the same host. This issue only affects docker version 1.13.1-108.git4ef4b30.el7, shipped in Red Hat Enterprise Linux 7 Extras. Both earlier and later versions are not affected.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jun 12, 2020
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Jun 17, 2026
Jun 3, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary co...Show more
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana process on the host system.Show less
3Fedoraproject
LinuxfoundationRedhat
4Cni Network Plugins
Enterprise LinuxFedora+1 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.0 MEDIUM· v3
6.0 MEDIUM· v2
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container ca...Show more
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
May 12, 2020
N/A· v4
6.6 MEDIUM· v3
4.6 MEDIUM· v2
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then u...Show more
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into the cluster via the WebUI or via the command line in the last 24 hours. Once the backup is older than 24 hours the OAuth tokens are no longer valid.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Apr 24, 2020
N/A· v4
5.9 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection bet...Show more
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing attack. The main threat from this vulnerability is data confidentiality.Show less
5Canonical
DebianFedoraproject+2 more
6Ceph
Ceph StorageDebian Linux+3 more
Jun 17, 2026
Apr 23, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
1Redhat
1Openshift Container Platform
Jun 17, 2026
Apr 22, 2020
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and writ...Show more
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is to data integrity.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraHaproxy+3 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly ca...Show more
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.Show less
2Buildah Project
Redhat
3Buildah
Enterprise LinuxOpenshift Container Platform
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's...Show more
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.Show less
3Debian
RedhatSystemd Project
7Ceph Storage
Debian LinuxDiscovery+4 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially crafted dbus messages.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Mar 9, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other tha...Show more
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/apb-tools-container.Show less
3Apache
FasterxmlRedhat
8Decision Manager
GeodeJackson Databind+5 more
Jun 17, 2026
Mar 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.Show less