CVEs (146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart. |
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Au...Show more |
2Redhat Smartbear3Jboss Fuse OpenshiftSwagger UiNov 21, 2024 Dec 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 swagger-ui has XSS in key names |
3Debian PuppetRedhat3Debian Linux Marionette CollectiveOpenshiftNov 21, 2024 Dec 13, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mcollective has a default password set at install |
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. |
4Debian OpensuseRedhat+1 more4Connect Debian LinuxOpenshift+1 moreNov 21, 2024 Dec 11, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware |
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS |
OpenShift cartridge allows remote URL retrieval |
2Phusion Redhat2Openshift PassengerNov 21, 2024 Nov 19, 2019 N/A· v4 7.5 HIGH· v3 6.4 MEDIUM· v2 RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. |
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution |
5Debian FedoraprojectPypa+2 more6Debian Linux FedoraOpenshift+3 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp. |
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a m...Show more |
2F5 Redhat2Container Ingress Service OpenshiftJun 17, 2026 Sep 4, 2019 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphr...Show more |
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more |
13Apache CanonicalD2iq+10 more19Backports Sle Container Development KitDc/os+16 moreJun 17, 2026 Feb 11, 2019 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as r...Show more |
3Canonical HaproxyRedhat5Enterprise Linux HaproxyOpenshift+2 moreNov 21, 2024 Sep 21, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service. |
2Kubernetes Redhat2Kubernetes OpenshiftNov 21, 2024 Sep 10, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by u...Show more |
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Aug 1, 2018 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally...Show more |
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for othe...Show more |