CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Dec 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one,...Show more |
2Heketi Project Redhat4Enterprise Linux Gluster StorageHeketi+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as g...Show more |
2Fedoraproject Redhat4Ceph Ceph StorageFedora+1 moreJun 17, 2026 Nov 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more |
3Fedoraproject Podman ProjectRedhat4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 5.3 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short dura...Show more |
8Canonical DebianGnu+5 more15Active Iq Unified Manager Debian LinuxEnterprise Linux+12 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |
2Docker Redhat3Docker Enterprise Linux ServerOpenshift Container PlatformJun 17, 2026 Jul 13, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304....Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Jun 12, 2020 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Jun 3, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary co...Show more |
3Fedoraproject LinuxfoundationRedhat4Cni Network Plugins Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container ca...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 May 12, 2020 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then u...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection bet...Show more |
5Canonical DebianFedoraproject+2 more6Ceph Ceph StorageDebian Linux+3 moreJun 17, 2026 Apr 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 22, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and writ...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraHaproxy+3 moreJun 17, 2026 Apr 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly ca...Show more |
2Buildah Project Redhat3Buildah Enterprise LinuxOpenshift Container PlatformJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's...Show more |
3Debian RedhatSystemd Project7Ceph Storage Debian LinuxDiscovery+4 moreJun 17, 2026 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Mar 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other tha...Show more |
3Apache FasterxmlRedhat8Decision Manager GeodeJackson Databind+5 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An atta...Show more |