Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 12 of 16
CVE-2021-20291P4MEDIUMCVSS 6.5v4.02021-04-01
CVE-2021-20291 [MEDIUM] CWE-667 CVE-2021-20291: A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. Whe
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which neve
nvd
CVE-2019-19353P4HIGHCVSS 7.0v4.02021-03-24
CVE-2019-19353 [HIGH] CWE-266 CVE-2019-19353: An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/h
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2019-19352P4HIGHCVSS 7.0v4.02021-03-24
CVE-2019-19352 [HIGH] CWE-266 CVE-2019-19352: An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/p
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
nvd
CVE-2020-14336P4MEDIUMCVSS 6.5v3.11v4.5.16+2 more2021-06-02
CVE-2020-14336 [MEDIUM] CWE-770 CVE-2020-14336: A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-15706P4MEDIUMCVSS 6.4v4.02020-07-29
CVE-2020-15706 [MEDIUM] CWE-362 CVE-2020-15706: GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnera
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and prior versions.
nvd
CVE-2019-10214P4MEDIUMCVSS 5.9v4.12019-11-25
CVE-2019-10214 [MEDIUM] CWE-522 CVE-2019-10214: The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Ente
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer
nvd
CVE-2022-4145P4MEDIUMCVSS 5.3v4.02023-10-05
CVE-2022-4145 [MEDIUM] CWE-74 CVE-2022-4145: A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthen
A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation.
nvd
CVE-2023-0264P4MEDIUMCVSS 5.0v4.9v4.102023-08-04
CVE-2023-0264 [MEDIUM] CWE-287 CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availabili
nvd
CVE-2018-13988P4MEDIUMCVSS 6.5v3.112018-07-25
CVE-2018-13988 [MEDIUM] CWE-125 CVE-2018-13988: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
nvd
CVE-2019-3826P4MEDIUMCVSS 6.1v3.112019-03-26
CVE-2019-3826 [MEDIUM] CWE-79 CVE-2019-3826: A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. A
A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persistent storage of arbitrary scripts.
nvd
CVE-2026-3441P4HIGHCVSS 7.1v4.02026-03-16
CVE-2026-3441 [HIGH] CWE-125 CVE-2026-3441: A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an ap
nvd
CVE-2020-15705P4MEDIUMCVSS 6.4v4.02020-07-29
CVE-2020-15705 [MEDIUM] CWE-347 CVE-2020-15705: GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects GRUB2 version 2.04 and prior versions
nvd
CVE-2020-14370P4MEDIUMCVSS 5.3v4.62020-09-23
CVE-2020-14370 [MEDIUM] CWE-212 CVE-2020-14370: An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. Whe
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control ov
nvd
CVE-2025-32989P4MEDIUMCVSS 5.3v4.02025-07-10
CVE-2025-32989 [MEDIUM] CWE-295 CVE-2025-32989: A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transpare
A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) extension during X.509 certificate parsing. This flaw allows a malicious user to create a certificate containing a malformed SCT extension (OID 1.3.6.1.4.1.11129.2.4.2) that contains sensitive data. This iss
nvd
CVE-2024-50312P4MEDIUMCVSS 5.3v4.02024-10-22
CVE-2024-50312 [MEDIUM] CWE-200 CVE-2024-50312: A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection qu
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors specific to the application's Graph
nvd
CVE-2018-1000864P4MEDIUMCVSS 6.5v3.112018-12-10
CVE-2018-1000864 [MEDIUM] CWE-835 CVE-2018-1000864: A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in Cr
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
nvd
CVE-2020-27777P4MEDIUMCVSS 6.7v4.4v4.5+1 more2020-12-15
CVE-2020-27777 [MEDIUM] CWE-862 CVE-2020-27777: A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.
nvd
CVE-2021-4294P4MEDIUMCVSS 5.9v4.02022-12-28
CVE-2021-4294 [MEDIUM] CWE-208 CVE-2021-4294: A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the
A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The
nvd
CVE-2023-6134P4MEDIUMCVSS 5.4v4.11v4.122023-12-14
CVE-2023-6134 [MEDIUM] CWE-79 CVE-2023-6134: A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildc
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
nvd
CVE-2023-5366P4MEDIUMCVSS 5.5v4.02023-10-06
CVE-2023-5366 [MEDIUM] CWE-345 CVE-2023-5366: A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual m
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
nvd