Redhat Openshift vulnerabilities
136 known vulnerabilities affecting redhat/openshift.
Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11
Vulnerabilities
Page 2 of 7
CVE-2015-5222P3HIGHCVSS 8.5v3.0.0.02015-08-24
CVE-2015-5222 [HIGH] CWE-264 CVE-2015-5222: Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authen
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.
nvd
CVE-2016-5418P3HIGHCVSS 7.5v3.1v3.22016-09-21
CVE-2016-5418 [HIGH] CWE-19 CVE-2016-5418: The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
nvd
CVE-2016-7075P3HIGHCVSS 8.1v3.1v3.2+1 more2018-09-10
CVE-2016-7075 [HIGH] CWE-295 CVE-2016-7075: It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 clie
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
nvd
CVE-2012-5646P3HIGHCVSS 7.5v1.02013-02-24
CVE-2012-5646 [HIGH] CWE-20 CVE-2012-5646: node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attacke
node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.
nvd
CVE-2014-3674P3HIGHCVSS 7.5≤ 2.1.8v2.0+14 more2014-11-13
CVE-2014-3674 [HIGH] CWE-264 CVE-2014-3674: Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows rem
Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of arbitrary gears via unspecified vectors.
nvd
CVE-2016-5766P3HIGHCVSS 8.8v2.02016-08-07
CVE-2016-5766 [HIGH] CWE-190 CVE-2016-5766: Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) be
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimens
nvd
CVE-2014-3666P3HIGHCVSS 7.5≤ 3.12014-10-16
CVE-2014-3666 [HIGH] CWE-94 CVE-2014-3666: Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
nvd
CVE-2016-0791P3CRITICALCVSS 9.8v3.12016-04-07
CVE-2016-0791 [CRITICAL] CWE-200 CVE-2016-0791: Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF toke
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
nvd
CVE-2012-6135P3HIGHCVSS 7.5v1.02019-11-19
CVE-2012-6135 [HIGH] CWE-20 CVE-2012-6135: RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
nvd
CVE-2026-35092P3HIGHCVSS 7.5v4.02026-04-01
CVE-2026-35092 [HIGH] CWE-190 CVE-2026-35092: A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity va
A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects Corosync deployments configured to use
nvd
CVE-2015-7538P3HIGHCVSS 8.8≤ 3.1v2.02016-02-03
CVE-2015-7538 [HIGH] CVE-2015-7538: Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mec
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
nvd
CVE-2022-3262P3HIGHCVSS 8.1v4.92022-12-08
CVE-2022-3262 [HIGH] CWE-453 CVE-2022-3262: A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
nvd
CVE-2015-1814P3HIGHCVSS 7.5≤ 3.12015-10-16
CVE-2015-1814 [HIGH] CWE-264 CVE-2015-1814: The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers
The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.
nvd
CVE-2021-4125P3HIGHCVSS 8.1≥ 4.6.0, < 4.6.52≥ 4.7.0, < 4.7.40+1 more2022-08-24
CVE-2021-4125 [HIGH] CWE-20 CVE-2021-4125: It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift mete
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
nvd
CVE-2013-4253P3HIGHCVSS 7.5v1.02022-10-19
CVE-2013-4253 [HIGH] CWE-377 CVE-2013-4253: The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Opensh
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
nvd
CVE-2018-10875P3HIGHCVSS 7.8v3.02018-07-13
CVE-2018-10875 [HIGH] CWE-426 CVE-2018-10875: A flaw was found in ansible. ansible.cfg is read from the current working directory which can be alt
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
nvd
CVE-2019-19350P3HIGHCVSS 7.8v3.11v4.02021-03-24
CVE-2019-19350 [HIGH] CWE-266 CVE-2019-19350: An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-se
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2015-7537P3HIGHCVSS 8.8≤ 3.1v2.02016-02-03
CVE-2015-7537 [HIGH] CWE-352 CVE-2015-7537: Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allow
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.
nvd
CVE-2016-8631P3HIGHCVSS 7.7v3.0v3.32018-07-31
CVE-2016-8631 [HIGH] CWE-20 CVE-2016-8631: The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes.
The OpenShift Enterprise 3 router does not properly sort routes when processing newly added routes. An attacker with access to create routes can potentially overwrite existing routes and redirect network traffic for other users to their own site.
nvd
CVE-2019-19349P3HIGHCVSS 7.8v4.02021-03-24
CVE-2019-19349 [HIGH] CWE-266 CVE-2019-19349: An insecure modification vulnerability in the /etc/passwd file was found in the container operator-f
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd