Redhat Openshift vulnerabilities
136 known vulnerabilities affecting redhat/openshift.
Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11
Vulnerabilities
Page 5 of 7
CVE-2019-19351P4HIGHCVSS 7.0v3.11v4.02020-03-18
CVE-2019-19351 [HIGH] CWE-266 CVE-2019-19351: An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in Openshift 4 and 3.11.
nvd
CVE-2016-0789P4MEDIUMCVSS 6.1v3.12016-04-07
CVE-2016-0789 [MEDIUM] CWE-20 CVE-2016-0789: CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
nvd
CVE-2014-3663P4MEDIUMCVSS 6.0≤ 3.12014-10-16
CVE-2014-3663 [MEDIUM] CWE-264 CVE-2014-3663: Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
nvd
CVE-2015-1810P4MEDIUMCVSS 4.6≤ 3.12015-10-16
CVE-2015-1810 [MEDIUM] CWE-264 CVE-2015-1810: The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restric
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.
nvd
CVE-2016-0790P4MEDIUMCVSS 5.3v3.12016-04-07
CVE-2016-0790 [MEDIUM] CWE-200 CVE-2016-0790: Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API token
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
nvd
CVE-2015-5318P4MEDIUMCVSS 6.8≤ 3.1v2.02015-11-25
CVE-2015-5318 [MEDIUM] CWE-352 CVE-2015-5318: Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protect
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack.
nvd
CVE-2020-1761P4MEDIUMCVSS 6.1fixed in 4.02021-05-27
CVE-2020-1761 [MEDIUM] CWE-358 CVE-2020-1761: A flaw was found in the OpenShift web console, where the access token is stored in the browser's loc
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
nvd
CVE-2023-0296P4MEDIUMCVSS 5.3v4.112023-01-17
CVE-2023-0296 [MEDIUM] CVE-2023-0296: The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health ch
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd grpc-proxy, hence this port might be conside
nvd
CVE-2021-3696P4MEDIUMCVSS 4.5v3.02022-07-06
CVE-2021-3696 [MEDIUM] CWE-787 CVE-2021-3696: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitr
nvd
CVE-2012-5622P4MEDIUMCVSS 6.8v0.0.52012-12-18
CVE-2012-5622 [MEDIUM] CWE-352 CVE-2012-5622: Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/con
Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.
nvd
CVE-2014-3662P4MEDIUMCVSS 5.0≤ 3.12014-10-16
CVE-2014-3662 [MEDIUM] CWE-200 CVE-2014-3662: Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vect
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
nvd
CVE-2019-3884P4MEDIUMCVSS 5.4v3.6v3.7+5 more2019-08-01
CVE-2019-3884 [MEDIUM] CWE-290 CVE-2019-3884: A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spo
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected.
nvd
CVE-2018-1059P4MEDIUMCVSS 6.1v3.02018-04-24
CVE-2018-1059 [MEDIUM] CWE-200 CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range i
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
nvd
CVE-2021-3695P4MEDIUMCVSS 4.5v3.02022-07-06
CVE-2021-3695 [MEDIUM] CWE-787 CVE-2021-3695: A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to
nvd
CVE-2013-7370P4MEDIUMCVSS 6.1v2.02019-12-11
CVE-2013-7370 [MEDIUM] CWE-79 CVE-2013-7370: node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
nvd
CVE-2015-5320P4MEDIUMCVSS 5.0≤ 3.1v2.02015-11-25
CVE-2015-5320 [MEDIUM] CWE-200 CVE-2015-5320: Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP sl
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
nvd
CVE-2016-3721P4MEDIUMCVSS 4.3v3.1v3.22016-05-17
CVE-2016-3721 [MEDIUM] CWE-17 CVE-2016-3721: Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
nvd
CVE-2017-7534P4MEDIUMCVSS 5.4v3.0v3.1+7 more2018-04-11
CVE-2017-7534 [MEDIUM] CWE-79 CVE-2017-7534: OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing the log files for a pod.
nvd
CVE-2013-4281P4MEDIUMCVSS 5.5v1.02022-10-19
CVE-2013-4281 [MEDIUM] CWE-276 CVE-2013-4281: In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem f
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
nvd
CVE-2019-14845P4MEDIUMCVSS 5.3≥ 4.1, ≤ 4.32019-10-08
CVE-2019-14845 [MEDIUM] CWE-494 CVE-2019-14845: A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source fr
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
nvd