Redhat Openshift vulnerabilities
136 known vulnerabilities affecting redhat/openshift.
Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11
Vulnerabilities
Page 3 of 7
CVE-2020-1709P3HIGHCVSS 7.8≥ 4.0, < 4.3v3.112020-03-20
CVE-2020-1709 [HIGH] CWE-732 CVE-2020-1709: A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecur
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2015-7539P3HIGHCVSS 7.5v2.0v3.12016-02-03
CVE-2015-7539 [HIGH] CWE-345 CVE-2015-7539: The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plu
The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.
nvd
CVE-2019-19345P3HIGHCVSS 7.8≥ 4.0, < 4.3v3.112020-03-20
CVE-2019-19345 [HIGH] CWE-266 CVE-2019-19345: A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an ins
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2021-4047P3HIGHCVSS 7.5v4.92022-04-11
CVE-2021-4047 [HIGH] CVE-2021-4047: The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch fo
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
nvd
CVE-2012-6685P3HIGHCVSS 7.5v2.02020-02-19
CVE-2012-6685 [HIGH] CWE-776 CVE-2012-6685: Nokogiri before 1.5.4 is vulnerable to XXE attacks
Nokogiri before 1.5.4 is vulnerable to XXE attacks
nvd
CVE-2016-3708P3HIGHCVSS 7.1v3.22016-06-08
CVE-2016-3708 [HIGH] CWE-284 CVE-2016-3708: Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.
nvd
CVE-2015-1806P3MEDIUMCVSS 6.5≤ 3.12015-10-16
CVE-2015-1806 [MEDIUM] CWE-264 CVE-2015-1806: The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote au
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
nvd
CVE-2015-5274P3MEDIUMCVSS 6.5v2.22015-09-18
CVE-2015-5274 [MEDIUM] CWE-77 CVE-2015-5274: rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execu
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
nvd
CVE-2022-2403P3MEDIUMCVSS 6.5≥ 4.9vOpenshift 4.9 onwards2022-09-01
CVE-2022-2403 [MEDIUM] CWE-497 CVE-2022-2403: A credentials leak was found in the OpenShift Container Platform. The private key for the external c
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-
nvd
CVE-2018-10885P3HIGHCVSS 7.5fixed in 3.10.92018-07-05
CVE-2018-10885 [HIGH] CWE-20 CVE-2018-10885: In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshi
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9, or 3.7 Cluster.
nvd
CVE-2014-0233P3MEDIUMCVSS 6.5v2.0v2.12014-11-16
CVE-2014-0233 [MEDIUM] CWE-94 CVE-2014-0233: Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to ex
Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme.
nvd
CVE-2016-2149P3MEDIUMCVSS 6.5v3.22016-06-08
CVE-2016-2149 [MEDIUM] CWE-200 CVE-2016-2149: Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another na
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
nvd
CVE-2023-0229P3MEDIUMCVSS 6.3v4.11v4.122023-01-26
CVE-2023-0229 [MEDIUM] CWE-20 CVE-2023-0229: A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to d
nvd
CVE-2018-14645P3HIGHCVSS 7.5v3.102018-09-21
CVE-2018-14645 [HIGH] CWE-125 CVE-2018-14645: A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An ou
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
nvd
CVE-2015-5325P3HIGHCVSS 7.5≤ 3.1v2.02015-11-25
CVE-2015-5325 [HIGH] CVE-2015-5325: Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master acces
Jenkins before 1.638 and LTS before 1.625.2 allow attackers to bypass intended slave-to-master access restrictions by leveraging a JNLP slave. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3665.
nvd
CVE-2022-3259P3HIGHCVSS 7.4v4.9v4.9.02022-12-09
CVE-2022-3259 [HIGH] CWE-665 CVE-2022-3259: Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
nvd
CVE-2016-5392P3MEDIUMCVSS 6.5v3.22016-08-05
CVE-2016-5392 [MEDIUM] CWE-200 CVE-2016-5392: The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environ
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.
nvd
CVE-2015-5305P3MEDIUMCVSS 6.4v3.02015-11-06
CVE-2015-5305 [MEDIUM] CWE-22 CVE-2015-5305: Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.
nvd
CVE-2019-10225P3MEDIUMCVSS 6.3v4.22021-03-19
CVE-2019-10225 [MEDIUM] CWE-522 CVE-2019-10225: A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Co
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service,
nvd
CVE-2016-5409P4HIGHCVSS 7.5v2.02017-04-20
CVE-2016-5409 [HIGH] CWE-200 CVE-2016-5409: Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEA
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.
nvd