CVEs (313)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Jun 12, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host...Show more |
1Redhat 2Openshift Container Platform Openshift Distributed TracingJun 17, 2026 Jun 5, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication. |
1Redhat 10Build Of Keycloak Jboss Middleware Text Only AdvisoriesKeycloak+7 moreJun 17, 2026 Apr 17, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive...Show more |
2Mholt Redhat3Advanced Cluster Security ArchiverOpenshift Container PlatformJun 17, 2026 Apr 6, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow th...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Arm64Openshift Container Platform For Ibm Z+2 moreJun 17, 2026 Mar 7, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a...Show more |
2Netapp Redhat9Active Iq Unified Manager FuseIntegration Camel For Spring Boot+6 moreJun 17, 2026 Feb 19, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then...Show more |
1Redhat 7Keycloak Migration Toolkit For ApplicationsOpenshift Container Platform+4 moreJun 17, 2026 Jan 26, 2024 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for...Show more |
A flaw was found in CRI-O that involves an experimental annotation leading to a container being unconfined. This may allow a pod to specify and get any amount of memory/cpu, circumventing the kubernetes scheduler and pot...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Ibm ZOpenshift Container Platform For Linuxone+2 moreJun 17, 2026 Dec 21, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin in...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Power+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.7 HIGH· v3 N/A· v2 An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an...Show more |
A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modifies the node role label could steer workloads from the control plane an...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
2Openvswitch Redhat5Enterprise Linux Fast DatapathOpenshift Container Platform+2 moreJun 17, 2026 Oct 6, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modif...Show more |
1Redhat 2Advanced Cluster Management For Kubernetes Openshift Container PlatformJun 17, 2026 Oct 5, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied. |
1Redhat 1Openshift Container Platform Jun 17, 2026 Oct 5, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation. |
2Ovn Redhat3Fast Datapath Open Virtual NetworkOpenshift Container PlatformJun 17, 2026 Oct 4, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properl...Show more |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Oct 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can a...Show more |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details...Show more |