cbcvebase.

Redhat Openshift vulnerabilities

136 known vulnerabilities affecting redhat/openshift.

Total CVEs
136
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
3
Severity breakdown
CRITICAL9HIGH52MEDIUM64LOW11

Vulnerabilities

Page 7 of 7
CVE-2014-3681P4MEDIUMCVSS 4.3≤ 3.12014-10-15
CVE-2014-3681 [MEDIUM] CWE-79 CVE-2014-3681: Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remot Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2015-5326P4MEDIUMCVSS 4.3≤ 3.1v2.02015-11-25
CVE-2015-5326 [MEDIUM] CWE-79 CVE-2015-5326: Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
nvd
CVE-2014-3680P4MEDIUMCVSS 4.0≤ 3.12014-10-16
CVE-2014-3680 [MEDIUM] CWE-200 CVE-2014-3680: Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ perm Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
nvd
CVE-2014-3667P4MEDIUMCVSS 4.0≤ 3.12014-10-16
CVE-2014-3667 [MEDIUM] CWE-200 CVE-2014-3667: Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
nvd
CVE-2012-5647P4MEDIUMCVSS 5.8v1.02013-02-24
CVE-2012-5647 [MEDIUM] CWE-20 CVE-2012-5647: Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1. Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.
nvd
CVE-2013-2119P4MEDIUMCVSS 4.6v1.02014-01-03
CVE-2013-2119 [MEDIUM] CWE-264 CVE-2013-2119: Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a de Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.
nvd
CVE-2016-8651P4LOWCVSS 3.5v3.02018-08-01
CVE-2016-8651 [LOW] CWE-20 CVE-2016-8651: An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
nvd
CVE-2017-7517P4LOWCVSS 3.5v3.02022-10-17
CVE-2017-7517 [LOW] CWE-20 CVE-2017-7517: An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.
nvd
CVE-2015-1808P4LOWCVSS 3.5≤ 3.12015-10-16
CVE-2015-1808 [LOW] CWE-20 CVE-2015-1808: Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of s Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
nvd
CVE-2015-7561P4LOWCVSS 3.1v3.02017-08-07
CVE-2015-7561 [LOW] CWE-264 CVE-2015-7561: Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.
nvd
CVE-2013-0164P4LOWCVSS 3.6≤ 1.02013-02-24
CVE-2013-0164 [LOW] CWE-264 CVE-2013-0164: The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
nvd
CVE-2015-0238P4LOWCVSS 3.3v2.02017-09-26
CVE-2015-0238 [LOW] CWE-200 CVE-2015-0238: selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing informa selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.
nvd
CVE-2016-3711P4LOWCVSS 3.3v3.22016-06-08
CVE-2016-3711 [LOW] CWE-200 CVE-2016-3711: HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the in HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie.
nvd
CVE-2014-0164P4LOWCVSS 2.1v1.2.7v2.0.52014-05-05
CVE-2014-0164 [LOW] CWE-310 CVE-2014-0164: openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-re openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information by reading the file.
nvd
CVE-2014-3602P4LOWCVSS 2.1≤ 2.1.8v2.0+14 more2014-11-13
CVE-2014-3602 [LOW] CWE-264 CVE-2014-3602: Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number info Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
nvd
CVE-2012-5658P4LOWCVSS 2.1≤ 1.02013-02-24
CVE-2012-5658 [LOW] CWE-310 CVE-2012-5658: rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the passwor rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.
nvd
Redhat Openshift vulnerabilities | cvebase