Redhat Openshift vulnerabilities
136 known vulnerabilities affecting redhat/openshift.
Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11
Vulnerabilities
Page 4 of 7
CVE-2021-3697P4HIGHCVSS 7.0v3.02022-07-06
CVE-2021-3697 [HIGH] CWE-787 CVE-2021-3697: A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlle
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution
nvd
CVE-2015-5323P4MEDIUMCVSS 6.5≤ 3.1v2.02015-11-25
CVE-2015-5323 [MEDIUM] CWE-264 CVE-2015-5323: Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which migh
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
nvd
CVE-2025-14512P4MEDIUMCVSS 6.5v4.02025-12-11
CVE-2025-14512 [MEDIUM] CWE-190 CVE-2025-14512: A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (Do
A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values.
nvd
CVE-2016-3724P4MEDIUMCVSS 6.5v3.1v3.22016-05-17
CVE-2016-3724 [MEDIUM] CWE-200 CVE-2016-3724: Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
nvd
CVE-2017-1000376P3HIGHCVSS 7.0v2.02017-06-19
CVE-2017-1000376 [HIGH] CWE-119 CVE-2017-1000376: libffi requests an executable stack allowing attackers to more easily trigger arbitrary code executi
libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. It was previously stated that this affects libffi version 3.2.1 but this appears to be incorrect. libffi prior to version 3.1 on 32 bit x86 systems was vuln
nvd
CVE-2015-5322P4MEDIUMCVSS 5.0≤ 3.1v2.02015-11-25
CVE-2015-5322 [MEDIUM] CWE-22 CVE-2015-5322: Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attac
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.
nvd
CVE-2015-7528P4MEDIUMCVSS 5.3v3.0v3.12016-04-11
CVE-2015-7528 [MEDIUM] CWE-200 CVE-2015-7528: Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container n
Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.
nvd
CVE-2016-3726P4HIGHCVSS 7.4v3.1v3.22016-05-17
CVE-2016-3726 [HIGH] CVE-2016-3726: Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote att
Multiple open redirect vulnerabilities in Jenkins before 2.3 and LTS before 1.651.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors related to "scheme-relative" URLs.
nvd
CVE-2015-5319P4MEDIUMCVSS 5.0≤ 3.1v2.02015-11-25
CVE-2015-5319 [MEDIUM] CVE-2015-5319: XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LT
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an "XML-aware tool," as demonstrated by get-job and update-job.
nvd
CVE-2020-1759P4MEDIUMCVSS 6.8v4.22020-04-13
CVE-2020-1759 [MEDIUM] CWE-323 CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 wher
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a
nvd
CVE-2018-1069P4HIGHCVSS 7.1v3.72018-03-09
CVE-2018-1069 [HIGH] CWE-284 CVE-2018-1069: Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container netw
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
nvd
CVE-2020-35514P4HIGHCVSS 7.0fixed in 4.7.0v4.7.02021-06-02
CVE-2020-35514 [HIGH] CWE-266 CVE-2020-35514: An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This fl
An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file and attempt to add their own node to the OpenShift cluster. The highest threat from this vulnerability is
nvd
CVE-2016-3703P4MEDIUMCVSS 5.3v3.1v3.22016-06-08
CVE-2016-3703 [MEDIUM] CWE-284 CVE-2016-3703: Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anony
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.
nvd
CVE-2013-4364P4HIGHCVSS 7.8v1.0v2.02018-01-08
CVE-2013-4364 [HIGH] CWE-59 CVE-2013-4364: (1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in R
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
nvd
CVE-2019-19348P4HIGHCVSS 7.0fixed in 3.11.188-4≥ 4.0.0, < 4.1.37+2 more2020-04-02
CVE-2019-19348 [HIGH] CWE-266 CVE-2019-19348: An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2020-1707P4HIGHCVSS 7.0≥ 4.0, < 4.32020-03-20
CVE-2020-1707 [HIGH] CWE-732 CVE-2020-1707: A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an in
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2024-45777P4MEDIUMCVSS 6.7v4.02025-02-19
CVE-2024-45777 [MEDIUM] CWE-787 CVE-2024-45777: A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo fil
A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2's sensitive heap data, eventually leading to the circumvention of secure boot protections.
nvd
CVE-2013-0196P4MEDIUMCVSS 6.5v1.22019-12-30
CVE-2013-0196 [MEDIUM] CWE-352 CVE-2013-0196: A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication'
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
nvd
CVE-2019-19346P4HIGHCVSS 7.0fixed in 3.11.188-4≥ 4.0.0, < 4.1.37+2 more2020-04-02
CVE-2019-19346 [HIGH] CWE-266 CVE-2019-19346: An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2019-19355P4HIGHCVSS 7.0v4.02020-03-18
CVE-2019-19355 [HIGH] CWE-266 CVE-2019-19355: An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-releas
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.
nvd