Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 10 of 16
CVE-2023-0056P3MEDIUMCVSS 6.5v4.12v4.10+1 more2023-03-23
CVE-2023-0056 [MEDIUM] CWE-400 CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the s
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
nvd
CVE-2024-4629P3MEDIUMCVSS 6.5v4.11v4.122024-09-03
CVE-2024-4629 [MEDIUM] CWE-837 CVE-2024-4629: A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection b
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses
nvd
CVE-2026-9150P3MEDIUMCVSS 6.5v4.02026-05-20
CVE-2026-9150 [MEDIUM] CWE-121 CVE-2026-9150: A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debi
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA512 checksum tags, leading to memory corruption and a denial of service (DoS) in the affected system.
nvd
CVE-2022-1632P3MEDIUMCVSS 6.5v4.0v4.8.172022-09-01
CVE-2022-1632 [MEDIUM] CWE-295 CVE-2022-1632: An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinatio
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
nvd
CVE-2026-0964P3MEDIUMCVSS 6.3v4.02026-03-26
CVE-2026-0964 [MEDIUM] CVE-2026-0964: A malicious SCP server can send unexpected paths that could make the client application override loc
A malicious SCP server can send unexpected paths that could make the
client application override local files outside of working directory.
This could be misused to create malicious executable or configuration
files and make the user execute them under specific consequences.
This is the same issue as in OpenSSH, tracked as CVE-2019-6111.
nvd
CVE-2018-14645P3HIGHCVSS 7.5v3.92018-09-21
CVE-2018-14645 [HIGH] CWE-125 CVE-2018-14645: A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An ou
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
nvd
CVE-2018-16540P3HIGHCVSS 7.8v3.112018-09-05
CVE-2018-16540 [HIGH] CWE-416 CVE-2018-16540: In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
nvd
CVE-2026-3012P3MEDIUMCVSS 6.8v4.02026-05-27
CVE-2026-3012 [MEDIUM] CWE-345 CVE-2026-3012: A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit th
nvd
CVE-2019-10225P3MEDIUMCVSS 6.3v3.11v4.02021-03-19
CVE-2019-10225 [MEDIUM] CWE-522 CVE-2019-10225: A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Co
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service,
nvd
CVE-2026-0990P3MEDIUMCVSS 5.9v4.02026-01-15
CVE-2026-0990 [MEDIUM] CWE-674 CVE-2026-0990: A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occur
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A remote attacker could exploit this configuration-dependent issue by providing a specially crafted XML catalog, leading to infinite recu
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v3.11v4.12018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2018-1070P4HIGHCVSS 7.5fixed in 3.102018-06-12
CVE-2018-1070 [HIGH] CWE-20 CVE-2018-1070: routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing c
routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.
nvd
CVE-2019-10223P4MEDIUMCVSS 6.5v3.11v4.1+1 more2019-11-05
CVE-2019-10223 [MEDIUM] CWE-200 CVE-2019-10223: A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimenta
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature c
nvd
CVE-2021-3697P4HIGHCVSS 7.0v4.6v4.9+1 more2022-07-06
CVE-2021-3697 [HIGH] CWE-787 CVE-2021-3697: A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlle
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution
nvd
CVE-2020-15707P4MEDIUMCVSS 6.4v4.02020-07-29
CVE-2020-15707 [MEDIUM] CWE-362 CVE-2020-15707: Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efili
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of arguments to the initrd command
nvd
CVE-2025-7519P3MEDIUMCVSS 6.7v4.02025-07-14
CVE-2025-7519 [MEDIUM] CWE-787 CVE-2025-7519: A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth,
A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not discarded. To exploit this flaw, a high-privilege account is needed as it's required to place the malicious policy f
nvd
CVE-2020-1726P4MEDIUMCVSS 5.9v4.32020-02-11
CVE-2020-1726 [MEDIUM] CWE-552 CVE-2020-1726: A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite exi
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to trigger the flaw and overwrite fil
nvd
CVE-2026-9149P4MEDIUMCVSS 6.5v4.02026-05-21
CVE-2026-9149 [MEDIUM] CWE-122 CVE-2026-9149: A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes
A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a subsequent out-of-bounds write. An attacker could exploit this to cause a denial of service (DoS).
nvd
CVE-2019-1002101P4MEDIUMCVSS 5.5v3.9v3.10+1 more2019-04-01
CVE-2019-1002101 [MEDIUM] CWE-59 CVE-2019-1002101: The kubectl cp command allows copying files between containers and the user machine. To copy files f
The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious result
nvd
CVE-2019-11255P4MEDIUMCVSS 6.5v3.11v4.1+1 more2019-12-05
CVE-2019-11255 [MEDIUM] CWE-20 CVE-2019-11255: Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and re
nvd