cbcvebase.

Redhat Openshift Container Platform vulnerabilities

312 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9

Vulnerabilities

Page 16 of 16
CVE-2019-1003014P4MEDIUMCVSS 4.8v3.112019-02-06
CVE-2019-1003014 [MEDIUM] CWE-79 CVE-2019-1003014: An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlie An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
nvd
CVE-2026-6845P4MEDIUMCVSS 5.0v4.02026-04-22
CVE-2026-6845 [MEDIUM] CWE-476 CVE-2026-6845: A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource con
nvd
CVE-2019-1003010P4MEDIUMCVSS 4.3v3.112019-02-06
CVE-2019-1003010 [MEDIUM] CWE-352 CVE-2019-1003010: A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/mai A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.
nvd
CVE-2021-20238P4LOWCVSS 3.7v4.02022-04-01
CVE-2021-20238 [LOW] CWE-287 CVE-2021-20238: It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Se It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets. There are two scenarios whe
nvd
CVE-2026-0989P4LOWCVSS 3.7v4.02026-01-15
CVE-2026-0989 [LOW] CWE-674 CVE-2026-0989: A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested directives. Specially crafted or overly complex schemas can cause excessive recursion during parsing. This may lead to stack exhaustion and application crashes, creating
nvd
CVE-2020-25639P4MEDIUMCVSS 4.4v4.4v4.5+1 more2021-03-04
CVE-2020-25639 [MEDIUM] CWE-476 CVE-2020-25639: A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
nvd
CVE-2016-8651P4LOWCVSS 3.5v3.1v3.2+1 more2018-08-01
CVE-2016-8651 [LOW] CWE-20 CVE-2016-8651: An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with An input validation flaw was found in the way OpenShift 3 handles requests for images. A user, with a copy of the manifest associated with an image, can pull an image even if they do not have access to the image normally, resulting in the disclosure of any information contained within the image.
nvd
CVE-2025-8283P4LOWCVSS 3.7v4.02025-07-28
CVE-2025-8283 [LOW] CWE-15 CVE-2025-8283: A vulnerability was found in the netavark package, a network stack for containers used with Podman. A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's
nvd
CVE-2026-0992P4LOWCVSS 2.9v4.02026-01-15
CVE-2026-0992 [LOW] CWE-400 CVE-2026-0992: A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly traverse catalog chains. This leads to excessive CPU c
nvd
CVE-2019-3815P4LOWCVSS 3.3v3.112019-01-28
CVE-2019-3815 [LOW] CVE-2019-3815: A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE=` entry. A local attacker may use this flaw to make systemd-journald crash. This issue only affects versions shipped with Re
nvd
CVE-2025-6170P4LOWCVSS 2.5v4.02025-06-16
CVE-2025-6170 [LOW] CWE-121 CVE-2025-6170: A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML fil A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
nvd
CVE-2019-10165P4LOWCVSS 2.3fixed in 4.1.32019-07-30
CVE-2019-10165 [LOW] CWE-532 CVE-2019-10165: OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources.
nvd
Redhat Openshift Container Platform vulnerabilities | cvebase