Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 15 of 16
CVE-2020-10763P4MEDIUMCVSS 5.5v4.02020-11-24
CVE-2020-10763 [MEDIUM] CWE-532 CVE-2020-10763: An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information.
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
nvd
CVE-2024-45778P4MEDIUMCVSS 5.5v4.02025-03-03
CVE-2024-45778 [MEDIUM] CWE-190 CVE-2024-45778: A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to
A stack overflow flaw was found when reading a BFS file system. A crafted BFS filesystem may lead to an uncontrolled loop, causing grub2 to crash.
nvd
CVE-2026-4897P4MEDIUMCVSS 5.5v4.02026-03-26
CVE-2026-4897 [MEDIUM] CWE-770 CVE-2026-4897: A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessiv
A flaw was found in polkit. A local user can exploit this by providing a specially crafted, excessively long input to the `polkit-agent-helper-1` setuid binary via standard input (stdin). This unbounded input can lead to an out-of-memory (OOM) condition, resulting in a Denial of Service (DoS) for the system.
nvd
CVE-2024-3056P4MEDIUMCVSS 4.8v4.02024-08-02
CVE-2024-3056 [MEDIUM] CWE-400 CVE-2024-3056: A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container
A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is out-of-memory (OOM) killed. While the maliciou
nvd
CVE-2019-10354P4MEDIUMCVSS 4.3v3.11v4.12019-07-17
CVE-2019-10354 [MEDIUM] CWE-862 CVE-2019-10354: A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earl
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
nvd
CVE-2020-10743P4MEDIUMCVSS 4.3v3.11.286v4.6.12021-06-02
CVE-2020-10743 [MEDIUM] CWE-358 CVE-2020-10743: It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in OCP's distribution of Kibana, such as clickjacking.
nvd
CVE-2026-5745P4MEDIUMCVSS 5.5v4.02026-04-07
CVE-2026-5745 [MEDIUM] CWE-476 CVE-2026-5745: A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing l
A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the function fails to perform adequate validation before advancing the pointer. An
nvd
CVE-2018-13033P4MEDIUMCVSS 5.5v3.112018-07-01
CVE-2018-13033 [MEDIUM] CWE-770 CVE-2018-13033: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows r
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.
nvd
CVE-2026-3832P4LOWCVSS 3.7v4.02026-04-30
CVE-2026-3832 [LOW] CWE-179 CVE-2026-3832: A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a speci
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a logic error in how gnutls processes multi-record OCSP responses, a client with OCSP verification enabled may incorrectly accept a revoked server certificate, p
nvd
CVE-2021-3669P4MEDIUMCVSS 5.5v4.6v4.7+1 more2022-08-26
CVE-2021-3669 [MEDIUM] CWE-400 CVE-2021-3669: A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
nvd
CVE-2021-20297P4MEDIUMCVSS 5.5v4.02021-05-26
CVE-2021-20297 [MEDIUM] CWE-20 CVE-2021-20297: A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a pr
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
nvd
CVE-2026-6844P4MEDIUMCVSS 5.5v4.02026-04-22
CVE-2026-6844 [MEDIUM] CWE-400 CVE-2026-6844: A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit tw
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-
nvd
CVE-2025-5917P4MEDIUMCVSS 5.0v4.02025-06-09
CVE-2025-5917 [MEDIUM] CWE-787 CVE-2025-5917: A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' mi
A vulnerability has been identified in the libarchive library. This flaw involves an 'off-by-one' miscalculation when handling prefixes and suffixes for file names. This can lead to a 1-byte write overflow. While seemingly small, such an overflow can corrupt adjacent memory, leading to unpredictable program behavior, crashes, or in specific circumstan
nvd
CVE-2018-1000862P4MEDIUMCVSS 4.3v3.112018-12-10
CVE-2018-1000862 [MEDIUM] CWE-200 CVE-2018-1000862: An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier i
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to browse the file system on agents running builds beyond the duration of the build using the workspace browser.
nvd
CVE-2022-0532P4MEDIUMCVSS 4.2v4.02022-02-09
CVE-2022-0532 [MEDIUM] CWE-732 CVE-2022-0532: An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
nvd
CVE-2019-10383P4MEDIUMCVSS 4.8v3.11v4.12019-08-28
CVE-2019-10383 [MEDIUM] CWE-79 CVE-2019-10383: A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier al
A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.
nvd
CVE-2019-10357P4MEDIUMCVSS 4.3v3.11v4.12019-07-31
CVE-2019-10357 [MEDIUM] CWE-862 CVE-2019-10357: A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allo
A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries.
nvd
CVE-2019-15718P4MEDIUMCVSS 4.4v4.12019-09-04
CVE-2019-15718 [MEDIUM] CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order
nvd
CVE-2026-6843P4MEDIUMCVSS 5.5v4.02026-04-22
CVE-2026-6843 [MEDIUM] CWE-134 CVE-2026-6843: A flaw was found in nano. A local user could exploit a format string vulnerability in the `statuslin
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By creating a directory with a name containing `printf` specifiers, the application attempts to display this name, leading to a segmentation fault (SEGV). This results in a Denial of Service (DoS) for the `nano` application.
nvd
CVE-2019-11244P4MEDIUMCVSS 5.0v3.11v4.12019-04-22
CVE-2019-11244 [MEDIUM] CWE-524 CVE-2019-11244: In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-
In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may be modified by other users/groups
nvd