← Back

Openshift Container Platform

openshift_container_platform

Vendor: Redhat • 326 CVEs

CVEs (326)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
Gpgme ProjectRedhat
9Enterprise Linux For Ibm Z Systems
Enterprise Linux For Power Little EndianEnterprise Linux Server+6 more
Jun 17, 2026
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signatu...Show more
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.Show less
5Canonical
DebianLinuxfoundation+2 more
5Debian Linux
LeapOpenshift Container Platform+2 more
Jun 17, 2026
Feb 12, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount...Show more
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that happens to block the attack.)Show less
2Libpod Project
Redhat
3Enterprise Linux
LibpodOpenshift Container Platform
Jun 17, 2026
Feb 11, 2020
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container bas...Show more
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite files in the volume.This issue was introduced in version 1.6.0.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Feb 7, 2020
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users oth...Show more
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privileges. This CVE is specific to the openshift/mysql-apb.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jan 7, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw ca...Show more
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Jan 7, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.Show less
8Canonical
DebianFedoraproject+5 more
15Backports Sle
ChromeCommunications Cloud Native Core Network Repository Function+12 more
Jun 17, 2026
Dec 10, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Kubernetes
Redhat
4External Provisioner
External ResizerExternal Snapshotter+1 more
Jun 17, 2026
Dec 5, 2019
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2)...Show more
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.Show less
1Redhat
1Openshift Container Platform
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discove...Show more
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.Show less
3Fedoraproject
KubernetesRedhat
3Cri O
FedoraOpenshift Container Platform
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.0 MEDIUM· v3
6.0 MEDIUM· v2
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of...Show more
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.Show less
5Buildah Project
Libpod ProjectOpensuse+2 more
6Buildah
Enterprise LinuxLeap+3 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.Show less
8Canonical
DebianF5+5 more
778Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+775 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local acces...Show more
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.Show less
2Kubernetes
Redhat
2Kube State Metrics
Openshift Container Platform
Jun 17, 2026
Nov 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-...Show more
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.Show less
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Element Software Management NodeEnterprise Linux+12 more
Jun 17, 2026
Oct 17, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For exa...Show more
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u \#$((0xffffffff))" command.Show less
2Kubernetes
Redhat
2Kubernetes
Openshift Container Platform
Jun 17, 2026
Oct 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API...Show more
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.Show less
6Debian
FedoraprojectGolang+3 more
9Cloud Insights Telegraf Agent
Debian LinuxDeveloper Tools+6 more
Jun 17, 2026
Sep 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
6Canonical
DockerFedoraproject+3 more
10Docker
Enterprise LinuxEnterprise Linux Eus+7 more
Jun 17, 2026
Sep 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image...Show more
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.Show less
8Canonical
DebianFedoraproject+5 more
34Aff A700s Firmware
Data Availability ServicesDebian Linux+31 more
Jun 17, 2026
Sep 17, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged gu...Show more
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host.Show less
5Artifex
DebianFedoraproject+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Jun 17, 2026
Sep 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more
A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
3Fedoraproject
RedhatSystemd Project
14Enterprise Linux
Enterprise Linux EusEnterprise Linux For Ibm Z Systems 8 S390x+11 more
Jun 17, 2026
Sep 4, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incomin...Show more
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order to change the system's DNS resolver settings.Show less