cbcvebase.

Redhat Openshift vulnerabilities

136 known vulnerabilities affecting redhat/openshift.

Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11

Vulnerabilities

Page 1 of 7
CVE-2015-5317P2HIGHCVSS 7.5KEVv2.0≤ 3.12015-11-25
CVE-2015-5317 [HIGH] CWE-200 CVE-2015-5317: The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers t The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
nvd
CVE-2015-7501P1CRITICALCVSS 9.8ExploitedPoCv3.02017-11-09
CVE-2015-7501 [CRITICAL] CWE-502 CVE-2015-7501: Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualiza Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Ha
nvd
CVE-2019-5736P1HIGHCVSS 8.6ExploitedPoCv3.4v3.5+2 more2019-02-11
CVE-2019-5736 [HIGH] CWE-78 CVE-2019-5736: runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overw runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to whi
nvd
CVE-2016-0792P2HIGHCVSS 8.8PoCv3.12016-04-07
CVE-2016-0792 [HIGH] CWE-20 CVE-2016-0792: Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authe Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
nvd
CVE-2015-5254P2CRITICALCVSS 9.8v2.02016-01-08
CVE-2015-5254 [CRITICAL] CWE-20 CVE-2015-5254: Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
nvd
CVE-2013-5123P3MEDIUMCVSS 5.9PoCv1.0v2.02019-11-05
CVE-2013-5123 [MEDIUM] CWE-287 CVE-2013-5123: The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and au The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
nvd
CVE-2013-2060P2CRITICALCVSS 9.8v1.02020-01-28
CVE-2013-2060 [CRITICAL] CWE-78 CVE-2013-2060: The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary comm The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
nvd
CVE-2016-0788P2CRITICALCVSS 9.8v3.12016-04-07
CVE-2016-0788 [CRITICAL] CWE-264 CVE-2016-0788: The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execut The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
nvd
CVE-2016-2074P3CRITICALCVSS 9.8v3.12016-07-03
CVE-2016-2074 [CRITICAL] CWE-119 CVE-2016-2074: Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
nvd
CVE-2016-2160P3HIGHCVSS 8.8v3.22016-06-08
CVE-2016-2160 [HIGH] CWE-264 CVE-2016-2160: Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute co Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.
nvd
CVE-2014-3496P3CRITICALCVSS 10.0v1.2.8v2.0+8 more2014-06-20
CVE-2014-3496 [CRITICAL] CWE-94 CVE-2014-3496: cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attacke cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file.
nvd
CVE-2014-0234P3CRITICALCVSS 9.8fixed in 2.12020-02-12
CVE-2014-0234 [CRITICAL] CVE-2014-0234: The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a passwo The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
nvd
CVE-2014-0163P3HIGHCVSS 8.8v1.0v2.02019-12-11
CVE-2014-0163 [HIGH] CWE-78 CVE-2014-0163: Openshift has shell command injection flaws due to unsanitized data being passed into shell commands Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
nvd
CVE-2013-2186P3HIGHCVSS 7.5≤ 3.12013-10-28
CVE-2013-2186 [HIGH] CWE-20 CVE-2013-2186: The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Port The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
nvd
CVE-2016-3738P3HIGHCVSS 8.8v3.22016-06-08
CVE-2016-3738 [HIGH] CWE-264 CVE-2016-3738: Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remot Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
nvd
CVE-2024-12085P3HIGHCVSS 7.5v5.02025-01-14
CVE-2024-12085 [HIGH] CWE-908 CVE-2024-12085: A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw all A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
nvd
CVE-2018-1102P3HIGHCVSS 8.8v3.0v3.1+8 more2018-04-30
CVE-2018-1102 [HIGH] CWE-20 CVE-2018-1102: A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper p A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
nvd
CVE-2024-1485P3CRITICALCVSS 9.3v4.02024-02-14
CVE-2024-1485 [CRITICAL] CWE-22 CVE-2024-1485: A flaw was found in the decompression function of registry-support. This issue can be triggered if a A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should
nvd
CVE-2026-35091P3HIGHCVSS 8.2v4.02026-04-01
CVE-2026-35091 [HIGH] CWE-253 CVE-2026-35091: A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vul A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and potentially disclosing limited memory conte
nvd
CVE-2014-0188P3HIGHCVSS 7.5≤ 1.2.7≥ 2.0, ≤ 2.0.52014-04-24
CVE-2014-0188 [HIGH] CWE-287 CVE-2014-0188: The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not prope The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to a passthrough trigger.
nvd
Redhat Openshift vulnerabilities | cvebase