VYPR

Openshift

by Red Hat

Source repositories

CVEs (194)

  • CVE-2020-1741MedApr 24, 2020
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could…

  • CVE-2019-10150MedJun 12, 2019
    risk 0.38cvss 5.9epss 0.01

    It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.

  • CVE-2013-4281MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

  • CVE-2013-0163MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS

  • CVE-2014-0084MedNov 21, 2019
    risk 0.36cvss 5.5epss 0.00

    Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.

  • CVE-2016-2142MedJun 8, 2016
    risk 0.36cvss 5.5epss 0.00

    Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.

  • CVE-2025-14512MedDec 11, 2025
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.

  • CVE-2013-5123MedNov 5, 2019
    risk 0.35cvss 5.9epss 0.08

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

  • CVE-2019-3884MedAug 1, 2019
    risk 0.35cvss 5.4epss 0.01

    A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.

  • CVE-2019-3889MedJul 11, 2019
    risk 0.35cvss 5.4epss 0.01

    A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to…

  • CVE-2018-1257MedMay 11, 2018
    risk 0.35cvss 6.5epss 0.03

    Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker)…

  • CVE-2017-7534MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.

  • CVE-2016-3703MedJun 8, 2016
    risk 0.35cvss 5.3epss 0.01

    Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an…

  • CVE-2016-0790MedApr 7, 2016
    risk 0.35cvss 5.3epss 0.02

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.

  • CVE-2025-14243MedApr 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in the OpenShift Mirror Registry. This vulnerability allows an unauthenticated, remote attacker to enumerate valid usernames and email addresses via different error messages during authentication failures and account creation.

  • CVE-2024-50312MedOct 22, 2024
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can…

  • CVE-2024-7128MedJul 26, 2024
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider ("openShiftAuth") is set, these functions do not perform any authentication checks,…

  • CVE-2023-0229MedJan 26, 2023
    risk 0.34cvss 6.3epss 0.01

    A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2…

  • CVE-2023-0296MedJan 17, 2023
    risk 0.34cvss 5.3epss 0.00

    The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary…

  • CVE-2019-14845MedOct 8, 2019
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.

Page 6 of 10