Red Hat Atomic-Openshift vulnerabilities
3 known vulnerabilities affecting red_hat/atomic-openshift.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2018-14632P3HIGHCVSS 7.7vatomic-openshift-3.72018-09-06
CVE-2018-14632 [HIGH] CWE-787 CVE-2018-14632: An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
nvd
CVE-2019-3889P4MEDIUMCVSS 5.4vopenshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.112019-07-11
CVE-2019-3889 [MEDIUM] CWE-79 CVE-2019-3889: A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions:
A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
nvd
CVE-2019-3884P4MEDIUMCVSS 5.4v3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 4.12019-08-01
CVE-2019-3884 [MEDIUM] CWE-290 CVE-2019-3884: A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spo
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
nvd