CVEs (146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause...Show more |
2Corosync Redhat3Corosync Enterprise LinuxOpenshiftJun 17, 2026 Apr 1, 2026 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (U...Show more |
2Gnome Redhat3Enterprise Linux GlibOpenshiftJul 13, 2026 Dec 11, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious fil...Show more |
2Gnu Redhat3Enterprise Linux Grub2OpenshiftJun 29, 2026 Feb 19, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by a...Show more |
8Almalinux ArchlinuxGentoo+5 more22Almalinux Arch LinuxEnterprise Linux+19 moreJul 20, 2026 Jan 14, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized...Show more |
2Devfile Redhat3Openshift Openshift Developer Tools And ServicesRegistry SupportJun 17, 2026 Feb 14, 2024 N/A· v4 9.3 CRITICAL· v3 N/A· v2 A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. Thi...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined."...Show more |
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to e...Show more |
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search polic...Show more |
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. |
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file. |
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file. |
An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later de...Show more |
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated Open...Show more |
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenSh...Show more |
2Gnu Redhat12Codeready Linux Builder Developer ToolsEnterprise Linux+9 moreJun 17, 2026 Jul 6, 2022 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap la...Show more |
3Gnu NetappRedhat13Codeready Linux Builder Developer ToolsEnterprise Linux+10 moreJun 17, 2026 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 6.9 MEDIUM· v2 A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low a...Show more |
4Fedoraproject GnuNetapp+1 more14Codeready Linux Builder Developer ToolsEnterprise Linux+11 moreJun 17, 2026 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure b...Show more |