cbcvebase.

Redhat Openshift Container Platform vulnerabilities

312 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9

Vulnerabilities

Page 13 of 16
CVE-2019-1003012P4MEDIUMCVSS 6.5v3.112019-02-06
CVE-2019-1003012 [MEDIUM] CWE-352 CVE-2019-1003012: A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueoce A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/m
nvd
CVE-2019-3876P4MEDIUMCVSS 6.3≥ 3.0, ≤ 3.112019-04-01
CVE-2019-3876 [MEDIUM] CWE-352 CVE-2019-3876: A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
nvd
CVE-2020-27816P4MEDIUMCVSS 6.1v4.02020-12-02
CVE-2020-27816 [MEDIUM] CWE-601 CVE-2020-27816: The elasticsearch-operator does not validate the namespace where kibana logging resource is created The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging c
nvd
CVE-2026-13757P4MEDIUMCVSS 6.2≥ 4.0, ≤ 4.22.12026-06-29
CVE-2026-13757 [MEDIUM] CWE-674 CVE-2026-13757: A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribu A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with
nvd
CVE-2020-1741P4MEDIUMCVSS 5.9v3.112020-04-24
CVE-2020-1741 [MEDIUM] CWE-185 CVE-2020-1741: A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing attack. The main threat from this vulnera
nvd
CVE-2017-12195P4MEDIUMCVSS 4.8v3.4v3.5+2 more2018-07-27
CVE-2017-12195 [MEDIUM] CWE-287 CVE-2017-12195: A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An a A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data
nvd
CVE-2026-10533P4MEDIUMCVSS 5.0v4.02026-06-01
CVE-2026-10533 [MEDIUM] CWE-770 CVE-2026-10533: A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not co A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance deg
nvd
CVE-2026-3442P4HIGHCVSS 7.1v4.02026-03-16
CVE-2026-3442 [HIGH] CWE-125 CVE-2026-3442: A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the
nvd
CVE-2025-5918P4MEDIUMCVSS 6.6v4.02025-06-09
CVE-2025-5918 [MEDIUM] CWE-125 CVE-2025-5918: A vulnerability has been identified in the libarchive library. This flaw can be triggered when file A vulnerability has been identified in the libarchive library. This flaw can be triggered when file streams are piped into bsdtar, potentially allowing for reading past the end of the file. This out-of-bounds read can lead to unintended consequences, including unpredictable program behavior, memory corruption, or a denial-of-service condition.
nvd
CVE-2020-1760P4MEDIUMCVSS 6.1v4.22020-04-23
CVE-2020-1760 [MEDIUM] CWE-79 CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
nvd
CVE-2016-1000232P4MEDIUMCVSS 5.3v3.1v3.2+1 more2018-09-05
CVE-2016-1000232 [MEDIUM] CWE-20 CVE-2016-1000232: NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP reques NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.
nvd
CVE-2019-3889P4MEDIUMCVSS 5.4≥ 3.4, ≤ 3.7≥ 3.9, ≤ 3.11+2 more2019-07-11
CVE-2019-3889 [MEDIUM] CWE-79 CVE-2019-3889: A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link.
nvd
CVE-2022-1274P4MEDIUMCVSS 5.4v4.9v4.102023-03-29
CVE-2022-1274 [MEDIUM] CWE-80 CVE-2022-1274: A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
nvd
CVE-2019-14891P4MEDIUMCVSS 5.0v3.11v4.1+1 more2019-11-25
CVE-2019-14891 [MEDIUM] CWE-460 CVE-2019-14891: A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
nvd
CVE-2021-3696P4MEDIUMCVSS 4.5v4.6v4.9+1 more2022-07-06
CVE-2021-3696 [MEDIUM] CWE-787 CVE-2021-3696: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitr
nvd
CVE-2025-5915P4MEDIUMCVSS 6.6v4.02025-06-09
CVE-2025-5915 [MEDIUM] CWE-122 CVE-2025-5915: A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer o A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may attempt to read beyond the allocated memory buffer, which can result in unpredictable program behavior, crashes (de
nvd
CVE-2026-4647P4MEDIUMCVSS 6.1v4.02026-03-23
CVE-2026-4647 [MEDIUM] CWE-125 CVE-2026-4647: A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds.
nvd
CVE-2019-1003013P4MEDIUMCVSS 5.4v3.112019-02-06
CVE-2019-1003013 [MEDIUM] CWE-79 CVE-2019-1003013: An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blu An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/expor
nvd
CVE-2018-10937P4MEDIUMCVSS 5.4v3.112018-09-11
CVE-2018-10937 [MEDIUM] CWE-79 CVE-2018-10937: A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform A cross site scripting flaw exists in the tetonic-console component of Openshift Container Platform 3.11. An attacker with the ability to create pods can use this flaw to perform actions on the K8s API as the victim.
nvd
CVE-2017-15137P4MEDIUMCVSS 5.3v3.92018-07-16
CVE-2017-15137 [MEDIUM] CWE-20 CVE-2017-15137: The OpenShift image import whitelist failed to enforce restrictions correctly when running commands The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
nvd
Redhat Openshift Container Platform vulnerabilities | cvebase