Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 4 of 16
CVE-2018-19362P3CRITICALCVSS 9.8v3.112019-01-02
CVE-2018-19362 [CRITICAL] CWE-502 CVE-2018-19362: FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leve
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.
nvd
CVE-2019-2684P3MEDIUMCVSS 5.9v3.112019-04-23
CVE-2019-2684 [MEDIUM] CVE-2019-2684: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2018-12023P3HIGHCVSS 7.5v3.112019-03-21
CVE-2018-12023 [HIGH] CWE-502 CVE-2018-12023: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.
nvd
CVE-2024-12085P3HIGHCVSS 7.5v4.12v4.13+4 more2025-01-14
CVE-2024-12085 [HIGH] CWE-908 CVE-2024-12085: A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw all
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.
nvd
CVE-2019-3899P3CRITICALCVSS 9.8v3.112019-04-22
CVE-2019-3899 [CRITICAL] CWE-592 CVE-2019-3899: It was found that default configuration of Heketi does not require any authentication potentially ex
It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11.
nvd
CVE-2026-5121P3HIGHCVSS 7.5v4.02026-03-30
CVE-2026-5121 [HIGH] CWE-190 CVE-2026-5121: A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the z
A flaw was found in libarchive. On 32-bit systems, an integer overflow vulnerability exists in the zisofs block pointer allocation logic. A remote attacker can exploit this by providing a specially crafted ISO9660 image, which can lead to a heap buffer overflow. This could potentially allow for arbitrary code execution on the affected system.
nvd
CVE-2018-10843P3HIGHCVSS 8.8fixed in 3.7.53v3.9+1 more2018-07-02
CVE-2018-10843 [HIGH] CWE-20 CVE-2018-10843: source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, a
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host whic
nvd
CVE-2022-0711P3HIGHCVSS 7.5v4.02022-03-02
CVE-2022-0711 [HIGH] CWE-835 CVE-2022-0711: A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. Th
A flaw was found in the way HAProxy processed HTTP responses containing the "Set-Cookie2" header. This flaw could allow an attacker to send crafted HTTP response packets which lead to an infinite loop, eventually resulting in a denial of service condition. The highest threat from this vulnerability is availability.
nvd
CVE-2018-19475P3HIGHCVSS 7.8v3.112018-11-23
CVE-2018-19475 [HIGH] CVE-2018-19475: psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access
psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same.
nvd
CVE-2019-11247P3HIGHCVSS 8.1v3.9v3.10+1 more2019-08-29
CVE-2019-11247 [HIGH] CWE-20 CVE-2019-11247: The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the re
The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings within the namespace, meaning that a user with access only to a resource in one namespace could create, v
nvd
CVE-2019-1003041P3CRITICALCVSS 9.8v3.112019-03-28
CVE-2019-1003041 [CRITICAL] CWE-470 CVE-2019-1003041: A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers
A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.
nvd
CVE-2018-12022P3HIGHCVSS 7.5v3.112019-03-21
CVE-2018-12022 [HIGH] CWE-502 CVE-2018-12022: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the servic
nvd
CVE-2026-46579P3HIGHCVSS 7.5v4.02026-05-29
CVE-2026-46579 [HIGH] CWE-287 CVE-2026-46579: A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Al
A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual
nvd
CVE-2026-33845P3CRITICALCVSS 9.1v4.02026-04-30
CVE-2026-33845 [CRITICAL] CWE-191 CVE-2026-33845: A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero off
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This issue is remotely exploitable and may cause information disclosure or denial of service.
nvd
CVE-2024-12088P3HIGHCVSS 7.5v4.02025-01-14
CVE-2024-12088 [HIGH] CWE-22 CVE-2024-12088: A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory.
nvd
CVE-2025-5372P3HIGHCVSS 8.8v4.02025-07-04
CVE-2025-5372 [HIGH] CWE-682 CVE-2025-5372: A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails
nvd
CVE-2022-1227P3HIGHCVSS 8.8v4.02022-04-29
CVE-2022-1227 [HIGH] CWE-281 CVE-2022-1227: A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or
nvd
CVE-2019-13734P3HIGHCVSS 8.8v3.11v4.22019-12-10
CVE-2019-13734 [HIGH] CWE-787 CVE-2019-13734: Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to po
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2026-4424P3HIGHCVSS 7.5v4.0v4.162026-03-19
CVE-2026-4424 [HIGH] CWE-125 CVE-2026-4424: A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive
A flaw was found in libarchive. This heap out-of-bounds read vulnerability exists in the RAR archive processing logic due to improper validation of the LZSS sliding window size after transitions between compression methods. A remote attacker can exploit this by providing a specially crafted RAR archive, leading to the disclosure of sensitive heap memory
nvd
CVE-2019-0542P3HIGHCVSS 8.8≥ 3.9, < 3.9.99≥ 3.10, < 3.10.163+1 more2019-01-09
CVE-2019-0542 [HIGH] CWE-94 CVE-2019-0542: A remote code execution vulnerability exists in Xterm.js when the component mishandles special chara
A remote code execution vulnerability exists in Xterm.js when the component mishandles special characters, aka "Xterm Remote Code Execution Vulnerability." This affects xterm.js.
nvd