Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 11 of 16
CVE-2023-27561P4HIGHCVSS 7.0v4.02023-03-03
CVE-2023-27561 [HIGH] CVE-2023-27561: runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libc
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
nvd
CVE-2021-3609P4HIGHCVSS 7.0v4.6v4.7+1 more2022-03-03
CVE-2021-3609 [HIGH] CWE-362 CVE-2021-3609: .A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can
.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the CAN subsystem to corrupt memory, crash the system or escalate privileges. This race condition in net/can/bcm.c in the Linux kernel allows for local privilege escalation to root.
nvd
CVE-2020-1708P4HIGHCVSS 7.0v3.11v4.1+2 more2020-02-07
CVE-2020-1708 [HIGH] CWE-266 CVE-2020-1708: It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their
nvd
CVE-2020-10749P4MEDIUMCVSS 6.0v4.02020-06-03
CVE-2020-10749 [MEDIUM] CWE-300 CVE-2020-10749: A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the maliciou
nvd
CVE-2024-50311P4MEDIUMCVSS 6.5v4.02024-10-22
CVE-2024-50311 [MEDIUM] CWE-770 CVE-2024-50311: A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploi
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue causes excessive resource consu
nvd
CVE-2025-5351P3MEDIUMCVSS 6.5v4.02025-07-04
CVE-2025-5351 [MEDIUM] CWE-415 CVE-2025-5351: A flaw was found in the key export functionality of libssh. The issue occurs in the internal functio
A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not cleared, leading to a potential double free issue if an additional failure occurs later in the function. This condition m
nvd
CVE-2021-3631P4MEDIUMCVSS 6.3v4.82022-03-02
CVE-2021-3631 [MEDIUM] CWE-732 CVE-2021-3631: A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. T
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
nvd
CVE-2026-12725P4MEDIUMCVSS 5.9≥ 4.0, ≤ 4.22.12026-06-22
CVE-2026-12725 [MEDIUM] CWE-122 CVE-2026-12725: A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both
A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and
query logging are both enabled, logging of DS or DNSKEY replies containing
unsupported algorithm or digest types can cause dnsmasq to write past the end
of an internal logging buffer. A remote attacker able to supply such a DNS
response may crash the dnsmasq process, resul
nvd
CVE-2021-3529P4HIGHCVSS 7.1v4.02021-06-02
CVE-2021-3529 [HIGH] CWE-79 CVE-2021-3529: A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitr
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. T
nvd
CVE-2022-2990P4HIGHCVSS 7.1v4.02022-09-13
CVE-2022-2990 [HIGH] CWE-842 CVE-2022-2990: An incorrect handling of the supplementary groups in the Buildah container engine might lead to the
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2022-2989P4HIGHCVSS 7.1v3.11v4.02022-09-13
CVE-2022-2989 [HIGH] CWE-842 CVE-2022-2989: An incorrect handling of the supplementary groups in the Podman container engine might lead to the s
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2019-19921P4HIGHCVSS 7.0v4.1v4.22020-02-12
CVE-2019-19921 [HIGH] CWE-706 CVE-2019-19921: runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due to an implementation detail that hap
nvd
CVE-2021-20188P4HIGHCVSS 7.0v3.112021-02-11
CVE-2021-20188 [HIGH] CWE-863 CVE-2021-20188: A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container. It does not allow to directly escape the containe
nvd
CVE-2020-1706P4HIGHCVSS 7.0v3.11v4.1+2 more2020-03-09
CVE-2020-1706 [HIGH] CWE-732 CVE-2020-1706: It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to add a user and escalate their privil
nvd
CVE-2019-10213P4MEDIUMCVSS 6.5v4.1v4.22019-11-25
CVE-2019-10213 [MEDIUM] CWE-117 CVE-2019-10213: OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod log
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
nvd
CVE-2023-2253P4MEDIUMCVSS 6.5v4.02023-06-06
CVE-2023-2253 [MEDIUM] CWE-475 CVE-2023-2253: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parame
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service t
nvd
CVE-2019-14854P4MEDIUMCVSS 6.5v4.1v4.22020-01-07
CVE-2019-14854 [MEDIUM] CWE-117 CVE-2019-14854: OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
nvd
CVE-2026-4426P4MEDIUMCVSS 6.5v4.02026-03-19
CVE-2026-4426 [MEDIUM] CWE-1335 CVE-2026-4426: A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompressi
A flaw was found in libarchive. An Undefined Behavior vulnerability exists in the zisofs decompression logic, caused by improper validation of a field (`pz_log2_bs`) read from ISO9660 Rock Ridge extensions. A remote attacker can exploit this by supplying a specially crafted ISO file. This can lead to incorrect memory allocation and potential applicat
nvd
CVE-2026-55653P4MEDIUMCVSS 6.5v4.02026-06-23
CVE-2026-55653 [MEDIUM] CWE-415 CVE-2026-55653: A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the D
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to c
nvd
CVE-2019-10150P4MEDIUMCVSS 5.9≥ 3.6, ≤ 4.12019-06-12
CVE-2019-10150 [MEDIUM] CWE-287 CVE-2019-10150: It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
nvd