Redhat Openshift Container Platform vulnerabilities
296 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
296
CISA KEV
8
actively exploited
Public exploits
23
Exploited in wild
8
Severity breakdown
CRITICAL38HIGH133MEDIUM118LOW7
Vulnerabilities
Page 13 of 15
CVE-2019-1003014MEDIUMCVSS 4.8v3.112019-02-06
CVE-2019-1003014 [MEDIUM] CWE-79 CVE-2019-1003014: An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlie
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
nvd
CVE-2019-3818HIGHCVSS 7.5v3.112019-02-05
CVE-2019-3818 [HIGH] CWE-327 CVE-2019-3818: The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform d
The kube-rbac-proxy container before version 0.4.1 as used in Red Hat OpenShift Container Platform does not honor TLS configurations, allowing for use of insecure ciphers and TLS 1.0. An attacker could target traffic sent over a TLS connection with a weak configuration and potentially break the encryption.
nvd
CVE-2019-3815LOWCVSS 3.3v3.112019-01-28
CVE-2019-3815 [LOW] CVE-2019-3815: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Re
nvd
CVE-2019-1003004HIGHCVSS 7.2v3.112019-01-22
CVE-2019-1003004 [HIGH] CVE-2019-1003004: An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/AuthenticationProcessingFilter2.java that allows attackers to extend the duration of active HTTP sessions indefinitely even though the user account may have been deleted in the mean time.
nvd
CVE-2019-1003002HIGHCVSS 8.8PoCv3.112019-01-22
CVE-2019-1003002 [HIGH] CVE-2019-1003002: A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Je
nvd
CVE-2019-1003003HIGHCVSS 7.2v3.112019-01-22
CVE-2019-1003003 [HIGH] CVE-2019-1003003: An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier
An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts
nvd
CVE-2019-1003000HIGHCVSS 8.8PoCv3.112019-01-22
CVE-2019-1003000 [HIGH] CVE-2019-1003000: A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/or
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.
nvd
CVE-2019-1003001HIGHCVSS 8.8PoCv3.112019-01-22
CVE-2019-1003001 [HIGH] CVE-2019-1003001: A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/o
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbi
nvd
CVE-2019-0542HIGHCVSS 8.8≥ 3.9, < 3.9.99≥ 3.10, < 3.10.163+1 more2019-01-09
CVE-2019-0542 [HIGH] CWE-94 CVE-2019-0542: A remote code execution vulnerability exists in Xterm.js when the component mishandles special chara
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
nvd
CVE-2018-14718CRITICALCVSS 9.8≥ 3.11, < 3.11.153≥ 4.6, < 4.6.26+2 more2019-01-02
CVE-2018-14718 [CRITICAL] CWE-502 CVE-2018-14718: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
nvd
CVE-2018-14719CRITICALCVSS 9.8≥ 3.11, < 3.11.153≥ 4.6, < 4.6.26+1 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2018-14720CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-14720 [CRITICAL] CWE-502 CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XX
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
nvd
CVE-2018-14721CRITICALCVSS 10.0v3.112019-01-02
CVE-2018-14721 [CRITICAL] CWE-918 CVE-2018-14721: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side requ
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
nvd
CVE-2018-19360CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19360 [CRITICAL] CWE-502 CVE-2018-19360: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
nvd
CVE-2018-19361CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19361 [CRITICAL] CWE-502 CVE-2018-19361: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
nvd
CVE-2018-19362CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19362 [CRITICAL] CWE-502 CVE-2018-19362: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
nvd
CVE-2018-17246CRITICALCVSS 9.8PoCv3.112018-12-20
CVE-2018-17246 [CRITICAL] CWE-73 CVE-2018-17246: Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plug
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.
nvd
CVE-2018-20102HIGHCVSS 7.5v3.112018-12-12
CVE-2018-20102 [HIGH] CWE-125 CVE-2018-20102: An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14
An out-of-bounds read in dns_validate_dns_response in dns.c was discovered in HAProxy through 1.8.14. Due to a missing check when validating DNS responses, remote attackers might be able read the 16 bytes corresponding to an AAAA record from the non-initialized part of the buffer, possibly accessing anything that was left on the stack, or even past th
nvd
CVE-2018-20103HIGHCVSS 7.5v3.112018-12-12
CVE-2018-20103 [HIGH] CWE-835 CVE-2018-20103: An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a c
An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
nvd
CVE-2018-18397MEDIUMCVSS 5.5PoCv3.112018-12-12
CVE-2018-18397 [MEDIUM] CWE-863 CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certa
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
nvd