Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 3 of 16
CVE-2019-1003034P3CRITICALCVSS 9.9v3.112019-03-08
CVE-2019-1003034 [CRITICAL] CVE-2019-1003034: A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src
A sandbox bypass vulnerability exists in Jenkins Job DSL Plugin 1.71 and earlier in job-dsl-core/src/main/groovy/javaposse/jobdsl/dsl/AbstractDslScriptLoader.groovy, job-dsl-plugin/build.gradle, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/JobDslWhitelist.groovy, job-dsl-plugin/src/main/groovy/javaposse/jobdsl/plugin/SandboxDslScriptLoader.g
nvd
CVE-2018-1085P3CRITICALCVSS 9.8fixed in 3.9.312018-06-15
CVE-2018-1085 [CRITICAL] CWE-592 CVE-2018-1085: openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the S
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER_CLIENT_CERT_AUTH in etcd.conf result in etcd being configured to allow remote users to connect without any authentication if they
nvd
CVE-2019-1003024P3HIGHCVSS 8.8v3.112019-02-20
CVE-2019-1003024 [HIGH] CVE-2019-1003024: A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectAS
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
nvd
CVE-2019-1003031P3CRITICALCVSS 9.9v3.112019-03-08
CVE-2019-1003031 [CRITICAL] CVE-2019-1003031: A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml,
A sandbox bypass vulnerability exists in Jenkins Matrix Project Plugin 1.13 and earlier in pom.xml, src/main/java/hudson/matrix/FilterScript.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM.
nvd
CVE-2020-27836P3CRITICALCVSS 9.8v4.62022-08-22
CVE-2020-27836 [CRITICAL] CWE-732 CVE-2020-27836: A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
nvd
CVE-2019-1010238P3CRITICALCVSS 9.8v3.11v4.12019-07-19
CVE-2019-1010238 [CRITICAL] CWE-787 CVE-2019-1010238: Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer ove
Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass invalid utf-8 strings to funct
nvd
CVE-2018-14720P3CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-14720 [CRITICAL] CWE-502 CVE-2018-14720: FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XX
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
nvd
CVE-2018-18311P3CRITICALCVSS 9.8v3.112018-12-07
CVE-2018-18311 [CRITICAL] CWE-190 CVE-2018-18311: Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression t
Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
nvd
CVE-2018-5968P3HIGHCVSS 8.1v4.1v3.112018-01-22
CVE-2018-5968 [HIGH] CVE-2018-5968: FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code
FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.
nvd
CVE-2021-3344P3HIGHCVSS 8.8≥ 4.5, < 4.5.33≥ 4.6, < 4.6.162021-03-16
CVE-2021-3344 [HIGH] CWE-522 CVE-2021-3344: A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside t
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary container images in internal registri
nvd
CVE-2021-20182P3HIGHCVSS 8.8≥ 4.4, < 4.4.33≥ 4.5, < 4.5.30+2 more2021-02-23
CVE-2021-20182 [HIGH] CWE-552 CVE-2021-20182: A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs wit
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the underlying node, such as the network and storage devices, to at least escalate th
nvd
CVE-2019-1003040P3CRITICALCVSS 9.8v3.112019-03-28
CVE-2019-1003040 [CRITICAL] CWE-470 CVE-2019-1003040: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers t
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
nvd
CVE-2019-10356P3HIGHCVSS 8.8v3.11v4.12019-07-31
CVE-2019-10356 [HIGH] CVE-2019-10356: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2019-10355P3HIGHCVSS 8.8v3.11v4.12019-07-31
CVE-2019-10355 [HIGH] CWE-704 CVE-2019-10355: A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the han
A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.
nvd
CVE-2022-4039P3CRITICALCVSS 9.8v4.9v4.102023-09-22
CVE-2022-4039 [CRITICAL] CWE-276 CVE-2022-4039: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
nvd
CVE-2018-11307P3CRITICALCVSS 9.8v3.11v4.12019-07-09
CVE-2018-11307 [CRITICAL] CWE-502 CVE-2018-11307: An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default ty
An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.
nvd
CVE-2018-1000866P3HIGHCVSS 8.8v3.112018-12-10
CVE-2018-1000866 [HIGH] CWE-269 CVE-2018-1000866: A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/cloudbees/groovy/cps/SandboxCpsTransformer.java that allows attackers with Job/Configure permission, or unauthorized attackers with SCM commit privile
nvd
CVE-2018-1000865P3HIGHCVSS 8.8v3.112018-12-10
CVE-2018-1000865 [HIGH] CWE-269 CVE-2018-1000865: A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/s
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Configure permission to execute arbitrary code on the Jenkins master JVM, if plugins using the Groovy sandbox are installed.
nvd
CVE-2018-19360P3CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19360 [CRITICAL] CWE-502 CVE-2018-19360: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.
nvd
CVE-2018-19361P3CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19361 [CRITICAL] CWE-502 CVE-2018-19361: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.
nvd