VYPR

Openshift

by Red Hat

Source repositories

CVEs (195)

  • CVE-2015-7501CriNov 9, 2017
    risk 0.71cvss 9.8epss 0.86

    Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform…

  • CVE-2023-44487HigKEVOct 10, 2023
    risk 0.65cvss 7.5epss 1.00

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • CVE-2013-2060CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.06

    The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.

  • CVE-2014-0175CriDec 13, 2019
    risk 0.64cvss 9.8epss 0.02

    mcollective has a default password set at install

  • CVE-2016-2074CriJul 3, 2016
    risk 0.64cvss 9.8epss 0.06

    Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.

  • CVE-2016-0791CriApr 7, 2016
    risk 0.64cvss 9.8epss 0.03

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.

  • CVE-2026-75885CriSep 18, 2026
    risk 0.60cvss 9.3epss 0.01

    A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the console pod makes requests to…

  • CVE-2019-5736HigFeb 11, 2019
    risk 0.60cvss 8.6epss 0.98

    runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new…

  • CVE-2016-0792HigApr 7, 2016
    risk 0.60cvss 8.8epss 0.83

    Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

  • CVE-2015-5254CriJan 8, 2016
    risk 0.60cvss 9.8epss 0.38

    Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

  • CVE-2016-5766HigAug 7, 2016
    risk 0.58cvss 8.8epss 0.07

    Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and…

  • CVE-2016-0788CriApr 7, 2016
    risk 0.58cvss 9.8epss 0.12

    The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

  • CVE-2026-92574HigSep 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities, no_new_privs, and seccomp state from the…

  • CVE-2026-1784HigJun 2, 2026
    risk 0.57cvss 8.8epss 0.00

    The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy…

  • CVE-2026-7374CriMay 26, 2026
    risk 0.57cvss 9.9epss 0.01

    A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket…

  • CVE-2021-3344HigMar 16, 2021
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use…

  • CVE-2014-0234CriFeb 12, 2020
    risk 0.57cvss 9.8epss 0.04

    The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before…

  • CVE-2019-14819HigJan 7, 2020
    risk 0.57cvss 8.8epss 0.01

    A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges…

  • CVE-2014-0163HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.02

    Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

  • CVE-2018-1102HigApr 30, 2018
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

Page 1 of 10