Redhat Openshift Container Platform vulnerabilities

271 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
271
CISA KEV
7
actively exploited
Public exploits
20
Exploited in wild
8
Severity breakdown
CRITICAL35HIGH124MEDIUM106LOW6

Vulnerabilities

Page 4 of 14
CVE-2023-4066MEDIUMCVSS 5.5v4.11v4.122023-09-27
CVE-2023-4066 [MEDIUM] CWE-313 CVE-2023-4066: A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-proper A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details yaml of AMQ Broker.
nvd
CVE-2023-1260HIGHCVSS 8.0v4.10v4.11+2 more2023-09-24
CVE-2023-1260 [HIGH] CWE-288 CVE-2023-1260: An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a re An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow eva
nvd
CVE-2022-4039CRITICALCVSS 9.8v4.9v4.102023-09-22
CVE-2022-4039 [CRITICAL] CWE-276 CVE-2022-4039: A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration.
nvd
CVE-2023-4853HIGHCVSS 8.1v4.10v4.11+1 more2023-09-20
CVE-2023-4853 [HIGH] CWE-148 CVE-2023-4853: A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permut A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
nvd
CVE-2022-3916MEDIUMCVSS 6.8v4.9v4.102023-09-20
CVE-2022-3916 [MEDIUM] CWE-384 CVE-2022-3916: A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared co A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authen
nvd
CVE-2022-3466MEDIUMCVSS 5.3v3.11v4.122023-09-15
CVE-2022-3466 [MEDIUM] CVE-2022-3466: The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11. The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433 and RHSA-2022:1600. This issue could allow
nvd
CVE-2023-1108HIGHCVSS 7.5v4.11v4.122023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd
CVE-2023-0264MEDIUMCVSS 5.0v4.9v4.102023-08-04
CVE-2023-0264 [MEDIUM] CWE-287 CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availabili
nvd
CVE-2022-4361MEDIUMCVSS 6.1v4.11v4.122023-07-07
CVE-2022-4361 [MEDIUM] CWE-81 CVE-2022-4361: Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) v Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
nvd
CVE-2023-3089HIGHCVSS 7.5v4.102023-07-05
CVE-2023-3089 [HIGH] CWE-693 CVE-2023-3089: A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
nvd
CVE-2023-2253MEDIUMCVSS 6.5v4.02023-06-06
CVE-2023-2253 [MEDIUM] CWE-475 CVE-2023-2253: A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parame A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service t
nvd
CVE-2023-1668HIGHCVSS 8.2v4.02023-04-10
CVE-2023-1668 [HIGH] CWE-670 CVE-2023-1668: A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will instal A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possi
nvd
CVE-2022-1274MEDIUMCVSS 5.4v4.9v4.102023-03-29
CVE-2022-1274 [MEDIUM] CWE-80 CVE-2022-1274: A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
nvd
CVE-2021-3684MEDIUMCVSS 5.5v4.62023-03-24
CVE-2021-3684 [MEDIUM] CWE-532 CVE-2021-3684: A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, i A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
nvd
CVE-2023-0056MEDIUMCVSS 6.5v4.12v4.10+1 more2023-03-23
CVE-2023-0056 [MEDIUM] CWE-400 CVE-2023-0056: An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the s An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
nvd
CVE-2023-27561HIGHCVSS 7.0v4.02023-03-03
CVE-2023-27561 [HIGH] CVE-2023-27561: runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libc runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
nvd
CVE-2021-4294MEDIUMCVSS 5.9v4.02022-12-28
CVE-2021-4294 [MEDIUM] CWE-208 CVE-2021-4294: A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The
nvd
CVE-2022-2989HIGHCVSS 7.1v3.11v4.02022-09-13
CVE-2022-2989 [HIGH] CWE-842 CVE-2022-2989: An incorrect handling of the supplementary groups in the Podman container engine might lead to the s An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2022-2990HIGHCVSS 7.1v4.02022-09-13
CVE-2022-2990 [HIGH] CWE-842 CVE-2022-2990: An incorrect handling of the supplementary groups in the Buildah container engine might lead to the An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2022-1632MEDIUMCVSS 6.5v4.0v4.8.172022-09-01
CVE-2022-1632 [MEDIUM] CWE-295 CVE-2022-1632: An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinatio An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
nvd