← Back

Openshift

openshift

Vendor: Redhat • 146 CVEs

CVEs (146)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Openshift
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
1Redhat
1Openshift
Nov 21, 2024
Dec 30, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Au...Show more
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.Show less
2Redhat
Smartbear
3Jboss Fuse
OpenshiftSwagger Ui
Nov 21, 2024
Dec 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
swagger-ui has XSS in key names
3Debian
PuppetRedhat
3Debian Linux
Marionette CollectiveOpenshift
Nov 21, 2024
Dec 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
mcollective has a default password set at install
1Redhat
1Openshift
Nov 21, 2024
Dec 11, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
4Debian
OpensuseRedhat+1 more
4Connect
Debian LinuxOpenshift+1 more
Nov 21, 2024
Dec 11, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
1Redhat
1Openshift
Nov 21, 2024
Dec 5, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
1Redhat
1Openshift
Nov 21, 2024
Dec 3, 2019
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
OpenShift cartridge allows remote URL retrieval
2Phusion
Redhat
2Openshift
Passenger
Nov 21, 2024
Nov 19, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
1Redhat
1Openshift
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
5Debian
FedoraprojectPypa+2 more
6Debian Linux
FedoraOpenshift+3 more
Nov 21, 2024
Nov 5, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
1Redhat
1Openshift
Nov 21, 2024
Nov 1, 2019
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
1Redhat
1Openshift
Jun 17, 2026
Oct 8, 2019
N/A· v4
5.3 MEDIUM· v3
2.9 LOW· v2
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a m...Show more
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.Show less
2F5
Redhat
2Container Ingress Service
Openshift
Jun 17, 2026
Sep 4, 2019
N/A· v4
4.4 MEDIUM· v3
1.9 LOW· v2
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphr...Show more
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration.Show less
1Redhat
1Openshift
Jun 17, 2026
Aug 1, 2019
N/A· v4
5.4 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.Show less
13Apache
CanonicalD2iq+10 more
19Backports Sle
Container Development KitDc/os+16 more
Jun 17, 2026
Feb 11, 2019
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.Show less
3Canonical
HaproxyRedhat
5Enterprise Linux
HaproxyOpenshift+2 more
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
2Kubernetes
Redhat
2Kubernetes
Openshift
Nov 21, 2024
Sep 10, 2018
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by u...Show more
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.Show less
1Redhat
2Openshift
Openshift Container Platform
Nov 21, 2024
Aug 1, 2018
N/A· v4
3.5 LOW· v3
2.7 LOW· v2
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally...Show more
An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.Show less
1Redhat
1Openshift
Nov 21, 2024
Jul 31, 2018
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for othe...Show more
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.Show less