cbcvebase.

Redhat Openshift vulnerabilities

136 known vulnerabilities affecting redhat/openshift.

Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11

Vulnerabilities

Page 6 of 7
CVE-2016-3723P4MEDIUMCVSS 4.3v3.1v3.22016-05-17
CVE-2016-3723 [MEDIUM] CWE-200 CVE-2016-3723: Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtai Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with read access to obtain sensitive plugin installation information by leveraging missing permissions checks in unspecified XML/JSON API endpoints.
nvd
CVE-2014-3664P4MEDIUMCVSS 4.0≤ 3.12014-10-15
CVE-2014-3664 [MEDIUM] CWE-22 CVE-2014-3664: Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authe Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
nvd
CVE-2015-5321P4MEDIUMCVSS 5.0≤ 3.1v2.02015-11-25
CVE-2015-5321 [MEDIUM] CWE-200 CVE-2015-5321: The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS bef The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
nvd
CVE-2015-5324P4MEDIUMCVSS 5.0v2.0≤ 3.12015-11-25
CVE-2015-5324 [MEDIUM] CWE-264 CVE-2015-5324: Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information v Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
nvd
CVE-2016-3727P4MEDIUMCVSS 4.3v3.1v3.22016-05-17
CVE-2016-3727 [MEDIUM] CWE-200 CVE-2016-3727: The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote aut The API URL computer/(master)/api/xml in Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users with extended read permission for the master node to obtain sensitive information about the global configuration via unspecified vectors.
nvd
CVE-2017-2611P4MEDIUMCVSS 4.3v2.0v3.02018-05-08
CVE-2017-2611 [MEDIUM] CWE-358 CVE-2017-2611: Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these background processes (that are otherwise performed daily), possibly causing additi
nvd
CVE-2016-2142P4MEDIUMCVSS 5.5v3.12016-06-08
CVE-2016-2142 [MEDIUM] CWE-200 CVE-2016-2142: Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-co Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.
nvd
CVE-2015-1807P4LOWCVSS 3.5≤ 3.12015-10-16
CVE-2015-1807 [LOW] CWE-22 CVE-2015-1807: Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authe Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.
nvd
CVE-2014-3661P4MEDIUMCVSS 5.0≤ 3.12014-10-16
CVE-2014-3661 [MEDIUM] CWE-399 CVE-2014-3661: Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (th Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
nvd
CVE-2015-1813P4MEDIUMCVSS 4.3≤ 3.12015-10-16
CVE-2015-1813 [MEDIUM] CVE-2015-1813: Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remot Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.
nvd
CVE-2015-1812P4MEDIUMCVSS 4.3≤ 3.12015-10-16
CVE-2015-1812 [MEDIUM] CWE-79 CVE-2015-1812: Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remot Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.
nvd
CVE-2016-9592P4MEDIUMCVSS 4.3v3.2.1.23v3.3.1.11+1 more2018-04-16
CVE-2016-9592 [MEDIUM] CWE-460 CVE-2016-9592: openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to det openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each volume, this could lead to a denial of service attack as the number of API requests being sent to the cloud-provider
nvd
CVE-2020-10715P4MEDIUMCVSS 4.3≥ 4.0, ≤ 4.3.5v3.112020-09-16
CVE-2020-10715 [MEDIUM] CWE-20 CVE-2020-10715: A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows a A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.
nvd
CVE-2019-19335P4MEDIUMCVSS 4.4v4.0v4.22020-03-18
CVE-2019-19335 [MEDIUM] CWE-732 CVE-2019-19335: During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vu
nvd
CVE-2014-1869P4MEDIUMCVSS 4.3≤ 3.12014-02-08
CVE-2014-1869 [MEDIUM] CWE-79 CVE-2014-1869: Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3 Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
nvd
CVE-2022-3260P4MEDIUMCVSS 4.8v4.92022-12-08
CVE-2022-3260 [MEDIUM] CWE-1021 CVE-2022-3260: The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attac The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
nvd
CVE-2021-3636P4MEDIUMCVSS 4.6fixed in 4.8vopenshift 4.82021-07-30
CVE-2021-3636 [MEDIUM] CWE-295 CVE-2021-3636: It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Ser It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclus
nvd
CVE-2013-0163P4MEDIUMCVSS 5.5v1.0v2.02019-12-05
CVE-2013-0163 [MEDIUM] CWE-668 CVE-2013-0163: OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate Do OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
nvd
CVE-2016-3725P4MEDIUMCVSS 4.3v3.1v3.22016-05-17
CVE-2016-3725 [MEDIUM] CWE-264 CVE-2016-3725: Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of u Jenkins before 2.3 and LTS before 1.651.2 allows remote authenticated users to trigger updating of update site metadata by leveraging a missing permissions check. NOTE: this issue can be combined with DNS cache poisoning to cause a denial of service (service disruption).
nvd
CVE-2016-3722P4MEDIUMCVSS 4.3v3.1v3.22016-05-17
CVE-2016-3722 [MEDIUM] CWE-264 CVE-2016-3722: Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with multiple accounts to cause a denial of service (unable to login) by editing the "full name."
nvd
Redhat Openshift vulnerabilities | cvebase