cbcvebase.

Redhat Openshift Container Platform vulnerabilities

312 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9

Vulnerabilities

Page 14 of 16
CVE-2022-27652P4MEDIUMCVSS 5.3v3.11v4.02022-04-18
CVE-2022-27652 [MEDIUM] CWE-276 CVE-2022-27652: A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissi A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those
nvd
CVE-2026-13595P4MEDIUMCVSS 5.3≥ 4.0, ≤ 4.22.12026-06-29
CVE-2026-13595 [MEDIUM] CWE-416 CVE-2026-13595: A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Mi A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use
nvd
CVE-2023-3153P4MEDIUMCVSS 5.3v4.02023-10-04
CVE-2023-3153 [MEDIUM] CWE-400 CVE-2023-3153: A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.
nvd
CVE-2019-10176P4MEDIUMCVSS 5.4v3.11v4.12019-08-02
CVE-2019-10176 [MEDIUM] CWE-352 CVE-2019-10176: A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
nvd
CVE-2023-4065P4MEDIUMCVSS 5.5v4.11v4.122023-09-27
CVE-2023-4065 [MEDIUM] CWE-117 CVE-2023-4065: A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQAr A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
nvd
CVE-2022-3466P4MEDIUMCVSS 5.3v3.11v4.122023-09-15
CVE-2022-3466 [MEDIUM] CVE-2022-3466: The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11. The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow
nvd
CVE-2017-15138P4MEDIUMCVSS 5.0v3.92018-08-13
CVE-2017-15138 [MEDIUM] CWE-200 CVE-2017-15138: The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with s The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
nvd
CVE-2025-4598P4MEDIUMCVSS 4.7v4.02025-05-30
CVE-2025-4598 [MEDIUM] CWE-364 CVE-2025-4598: A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/shadow content, loaded by the original process. A SUID binary or process has a special type o
nvd
CVE-2021-3695P4MEDIUMCVSS 4.5v4.6v4.9+1 more2022-07-06
CVE-2021-3695 [MEDIUM] CWE-787 CVE-2021-3695: A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to
nvd
CVE-2018-3830P4MEDIUMCVSS 6.1v3.112018-09-19
CVE-2018-3830 [MEDIUM] CWE-79 CVE-2018-3830: Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field f Kibana versions 5.3.0 to 6.4.1 had a cross-site scripting (XSS) vulnerability via the source field formatter that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.
nvd
CVE-2022-0669P4MEDIUMCVSS 6.5v4.02022-08-29
CVE-2022-0669 [MEDIUM] CWE-400 CVE-2022-0669: A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected num A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave proc
nvd
CVE-2022-4361P4MEDIUMCVSS 6.1v4.11v4.122023-07-07
CVE-2022-4361 [MEDIUM] CWE-81 CVE-2022-4361: Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) v Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
nvd
CVE-2019-1003050P4MEDIUMCVSS 5.4v3.112019-04-10
CVE-2019-1003050 [MEDIUM] CWE-79 CVE-2019-1003050: The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.1 The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
nvd
CVE-2025-5916P4MEDIUMCVSS 5.6v4.02025-06-09
CVE-2025-5916 [MEDIUM] CWE-190 CVE-2025-5916: A vulnerability has been identified in the libarchive library. This flaw involves an integer overflo A vulnerability has been identified in the libarchive library. This flaw involves an integer overflow that can be triggered when processing a Web Archive (WARC) file that claims to have more than INT64_MAX - 4 content bytes. An attacker could craft a malicious WARC archive to induce this overflow, potentially leading to unpredictable program behavior,
nvd
CVE-2021-3684P4MEDIUMCVSS 5.5v4.62023-03-24
CVE-2021-3684 [MEDIUM] CWE-532 CVE-2021-3684: A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, i A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
nvd
CVE-2022-0718P4MEDIUMCVSS 4.9v4.02022-08-29
CVE-2022-0718 [MEDIUM] CWE-522 CVE-2022-0718: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
nvd
CVE-2024-9675P4MEDIUMCVSS 4.4v4.13v4.14+3 more2024-10-09
CVE-2024-9675 [MEDIUM] CWE-22 CVE-2024-9675: A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified path A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.
nvd
CVE-2023-4066P4MEDIUMCVSS 5.5v4.11v4.122023-09-27
CVE-2023-4066 [MEDIUM] CWE-313 CVE-2023-4066: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-proper A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
nvd
CVE-2018-12207P4MEDIUMCVSS 6.5v4.1v4.22019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel( Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2026-7309P4MEDIUMCVSS 4.3v4.02026-04-28
CVE-2026-7309 [MEDIUM] CWE-426 CVE-2026-7309: A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRol A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantiate` API. This incomplete fix for a previous vulnerability allows for information disclosure, specifical
nvd
Redhat Openshift Container Platform vulnerabilities | cvebase