Redhat Openshift Container Platform vulnerabilities

271 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
271
CISA KEV
7
actively exploited
Public exploits
20
Exploited in wild
8
Severity breakdown
CRITICAL35HIGH124MEDIUM106LOW6

Vulnerabilities

Page 12 of 14
CVE-2019-1003003HIGHCVSS 7.2v3.112019-01-22
CVE-2019-1003003 [HIGH] CVE-2019-1003003: An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts
nvd
CVE-2019-1003000HIGHCVSS 8.8PoCv3.112019-01-22
CVE-2019-1003000 [HIGH] CVE-2019-1003000: A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/or A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
nvd
CVE-2019-1003001HIGHCVSS 8.8PoCv3.112019-01-22
CVE-2019-1003001 [HIGH] CVE-2019-1003001: A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/o A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbi
nvd
CVE-2019-0542HIGHCVSS 8.8≥ 3.9, < 3.9.99≥ 3.10, < 3.10.163+1 more2019-01-09
CVE-2019-0542 [HIGH] CWE-94 CVE-2019-0542: A remote code execution vulnerability exists in Xterm.js when the component mishandles special chara A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
nvd
CVE-2018-14718CRITICALCVSS 9.8≥ 3.11, < 3.11.153≥ 4.6, < 4.6.26+2 more2019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvd
CVE-2018-14719CRITICALCVSS 9.8≥ 3.11, < 3.11.153≥ 4.6, < 4.6.26+1 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2018-14720CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-14720 [CRITICAL] CWE-502 CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XX FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
nvd
CVE-2018-14721CRITICALCVSS 10.0v3.112019-01-02
CVE-2018-14721 [CRITICAL] CWE-918 CVE-2018-14721: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side requ FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
nvd
CVE-2018-19360CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19360 [CRITICAL] CWE-502 CVE-2018-19360: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
nvd
CVE-2018-19361CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19361 [CRITICAL] CWE-502 CVE-2018-19361: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
nvd
CVE-2018-19362CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19362 [CRITICAL] CWE-502 CVE-2018-19362: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
nvd
CVE-2018-17246CRITICALCVSS 9.8PoCv3.112018-12-20
CVE-2018-17246 [CRITICAL] CWE-73 CVE-2018-17246: Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plug Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
nvd
CVE-2018-20102HIGHCVSS 7.5v3.112018-12-12
CVE-2018-20102 [HIGH] CWE-125 CVE-2018-20102: An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14 An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past th
nvd
CVE-2018-20103HIGHCVSS 7.5v3.112018-12-12
CVE-2018-20103 [HIGH] CWE-835 CVE-2018-20103: An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a c An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
nvd
CVE-2018-18397MEDIUMCVSS 5.5PoCv3.112018-12-12
CVE-2018-18397 [MEDIUM] CWE-863 CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certa The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
nvd
CVE-2018-1000861CRITICALCVSS 9.8KEVPoCv3.112018-12-10
CVE-2018-1000861 [CRITICAL] CWE-502 CVE-2018-1000861: A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.
nvd
CVE-2018-1000866HIGHCVSS 8.8v3.112018-12-10
CVE-2018-1000866 [HIGH] CWE-269 CVE-2018-1000866: A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/ A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privile
nvd
CVE-2018-1000865HIGHCVSS 8.8v3.112018-12-10
CVE-2018-1000865 [HIGH] CWE-269 CVE-2018-1000865: A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/s A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.
nvd
CVE-2018-1000863HIGHCVSS 8.2v3.112018-12-10
CVE-2018-1000863 [HIGH] CWE-22 CVE-2018-1000863: A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in Us A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
nvd
CVE-2018-1000864MEDIUMCVSS 6.5v3.112018-12-10
CVE-2018-1000864 [MEDIUM] CWE-835 CVE-2018-1000864: A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in Cr A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
nvd