Openshift
by Red Hat
Source repositories
CVEs (194)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-3738 | Hig | 0.57 | 8.8 | 0.02 | Jun 8, 2016 | Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod. | ||
| CVE-2015-5317 | Hig | 0.56 | 7.5 | 0.23 | KEV | Nov 25, 2015 | The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request. | |
| CVE-2018-10843 | Hig | 0.55 | 8.5 | 0.01 | Jul 2, 2018 | source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this… | ||
| CVE-2025-3528 | Hig | 0.53 | 8.2 | 0.00 | May 9, 2025 | A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to… | ||
| CVE-2022-3262 | Hig | 0.53 | 8.1 | 0.01 | Dec 8, 2022 | A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability. | ||
| CVE-2013-2103 | Hig | 0.53 | 8.1 | 0.01 | Dec 3, 2019 | OpenShift cartridge allows remote URL retrieval | ||
| CVE-2013-4561 | Cri | 0.52 | 9.1 | 0.01 | Jun 30, 2022 | In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity. | ||
| CVE-2019-19354 | Hig | 0.51 | 7.8 | 0.00 | Mar 24, 2021 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | ||
| CVE-2019-19350 | Hig | 0.51 | 7.8 | 0.00 | Mar 24, 2021 | An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | ||
| CVE-2019-19349 | Hig | 0.51 | 7.8 | 0.00 | Mar 24, 2021 | An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | ||
| CVE-2014-0023 | Hig | 0.51 | 7.8 | 0.00 | Nov 15, 2019 | OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution | ||
| CVE-2013-4364 | Hig | 0.51 | 7.8 | 0.00 | Jan 8, 2018 | (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp. | ||
| CVE-2016-2160 | Hig | 0.51 | 8.8 | 0.04 | Jun 8, 2016 | Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image. | ||
| CVE-2021-20182 | Hig | 0.50 | 8.8 | 0.01 | Feb 23, 2021 | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the… | ||
| CVE-2015-7538 | Hig | 0.50 | 8.8 | 0.02 | Feb 3, 2016 | Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors. | ||
| CVE-2015-7537 | Hig | 0.50 | 8.8 | 0.02 | Feb 3, 2016 | Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method. | ||
| CVE-2026-18381 | Hig | 0.49 | 7.6 | 0.00 | Jul 30, 2026 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries… | ||
| CVE-2024-45497 | Hig | 0.49 | 7.6 | 0.01 | Dec 31, 2024 | A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from… | ||
| CVE-2013-4253 | Hig | 0.49 | 7.5 | 0.01 | Oct 19, 2022 | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file. | ||
| CVE-2021-4047 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. |
- risk 0.57cvss 8.8epss 0.02
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
- risk 0.56cvss 7.5epss 0.23
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
- risk 0.55cvss 8.5epss 0.01
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this…
- risk 0.53cvss 8.2epss 0.00
A flaw was found in the Mirror Registry. The quay-app container shipped as part of the Mirror Registry for OpenShift has write access to the `/etc/passwd`. This flaw allows a malicious actor with access to the container to modify the passwd file and elevate their privileges to…
- risk 0.53cvss 8.1epss 0.01
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
- risk 0.53cvss 8.1epss 0.01
OpenShift cartridge allows remote URL retrieval
- risk 0.52cvss 9.1epss 0.01
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
- risk 0.51cvss 7.8epss 0.00
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
- risk 0.51cvss 7.8epss 0.00
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
- risk 0.51cvss 7.8epss 0.00
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
- risk 0.51cvss 7.8epss 0.00
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
- risk 0.51cvss 7.8epss 0.00
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
- risk 0.51cvss 8.8epss 0.04
Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.
- risk 0.50cvss 8.8epss 0.01
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the…
- risk 0.50cvss 8.8epss 0.02
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
- risk 0.50cvss 8.8epss 0.02
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.
- risk 0.49cvss 7.6epss 0.00
A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries…
- risk 0.49cvss 7.6epss 0.01
A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from…
- risk 0.49cvss 7.5epss 0.01
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
- risk 0.49cvss 7.5epss 0.01
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
Page 2 of 10