CVEs (146)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Jul 16, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that shoul...Show more |
4Canonical DebianRedhat+1 more10Ansible Engine Ceph StorageDebian Linux+7 moreNov 21, 2024 Jul 13, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execu...Show more |
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS...Show more |
3Oracle RedhatVmware30Agile Product Lifecycle Management Application Testing SuiteBig Data Discovery+27 moreNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through t...Show more |
2Jenkins Redhat2Jenkins OpenshiftNov 21, 2024 May 8, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing...Show more |
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation. |
3Canonical DpdkRedhat9Ceph Storage Data Plane Development KitEnterprise Linux+6 moreNov 21, 2024 Apr 24, 2018 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead t...Show more |
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30...Show more |
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable link...Show more |
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on t...Show more |
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified...Show more |
1Redhat 15Data Grid Jboss A MqJboss Bpm Suite+12 moreMay 13, 2026 Nov 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Ope...Show more |
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack. |
2Kubernetes Redhat2Kubernetes OpenshiftMay 13, 2026 Aug 7, 2017 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image. |
4Debian Libffi ProjectOracle+1 more6Debian Linux Enterprise LinuxEnterprise Virtualization Server+3 moreMay 13, 2026 Jun 19, 2017 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated th...Show more |
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to...Show more |
3Libarchive OracleRedhat10Enterprise Linux Desktop Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+7 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. |
5Debian FedoraprojectFreebsd+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Aug 7, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more |
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user inform...Show more |
2Openvswitch Redhat2Openshift OpenvswitchMay 6, 2026 Jul 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long stri...Show more |