VYPR

OpenShift Console

by Red Hat

CVEs (3)

  • CVE-2026-50237HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined…

  • CVE-2026-50236HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's…

  • CVE-2020-1761MedMay 27, 2021
    risk 0.40cvss 6.1epss 0.01

    A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions…