VYPR

Openshift

by Red Hat

Source repositories

CVEs (191)

  • CVE-2025-3528HigMay 9, 2025
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to…

  • CVE-2022-3262HigDec 8, 2022
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

  • CVE-2013-2103HigDec 3, 2019
    risk 0.53cvss 8.1epss 0.01

    OpenShift cartridge allows remote URL retrieval

  • CVE-2013-4561CriJun 30, 2022
    risk 0.52cvss 9.1epss 0.01

    In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

  • CVE-2019-19354HigMar 24, 2021
    risk 0.51cvss 7.8epss 0.00

    An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

  • CVE-2019-19350HigMar 24, 2021
    risk 0.51cvss 7.8epss 0.00

    An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

  • CVE-2019-19349HigMar 24, 2021
    risk 0.51cvss 7.8epss 0.00

    An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

  • CVE-2014-0023HigNov 15, 2019
    risk 0.51cvss 7.8epss 0.00

    OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

  • CVE-2013-4364HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.

  • CVE-2016-2160HigJun 8, 2016
    risk 0.51cvss 8.8epss 0.04

    Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.

  • CVE-2021-20182HigFeb 23, 2021
    risk 0.50cvss 8.8epss 0.01

    A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the…

  • CVE-2015-7538HigFeb 3, 2016
    risk 0.50cvss 8.8epss 0.02

    Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.

  • CVE-2015-7537HigFeb 3, 2016
    risk 0.50cvss 8.8epss 0.02

    Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.

  • CVE-2026-18381HigJul 30, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries…

  • CVE-2024-45497HigDec 31, 2024
    risk 0.49cvss 7.6epss 0.01

    A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from…

  • CVE-2013-4253HigOct 19, 2022
    risk 0.49cvss 7.5epss 0.01

    The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

  • CVE-2021-4047HigApr 11, 2022
    risk 0.49cvss 7.5epss 0.01

    The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.

  • CVE-2012-6685HigFeb 19, 2020
    risk 0.49cvss 7.5epss 0.02

    Nokogiri before 1.5.4 is vulnerable to XXE attacks

  • CVE-2018-14645HigSep 21, 2018
    risk 0.49cvss 7.5epss 0.03

    A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

  • CVE-2016-7075HigSep 10, 2018
    risk 0.49cvss 7.5epss 0.02

    It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.

Page 2 of 10