Redhat Openshift Container Platform vulnerabilities
312 known vulnerabilities affecting redhat/openshift_container_platform.
Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9
Vulnerabilities
Page 5 of 16
CVE-2020-25660P3HIGHCVSS 8.8v4.02020-11-23
CVE-2020-25660 [HIGH] CVE-2020-25660: A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14,
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by t
nvd
CVE-2025-5318P3HIGHCVSS 8.1v4.02025-06-24
CVE-2025-5318 [HIGH] CWE-125 CVE-2025-5318: A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be tr
A flaw was found in the libssh library in versions less than 0.11.2. An out-of-bounds read can be triggered in the sftp_handle function due to an incorrect comparison check that permits the function to access memory beyond the valid handle list and to return an invalid pointer, which is used in further processing. This vulnerability allows an authentica
nvd
CVE-2026-1784P3HIGHCVSS 8.8v4.02026-06-02
CVE-2026-1784 [HIGH] CWE-15 CVE-2026-1784: The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through H
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
nvd
CVE-2023-1260P3HIGHCVSS 8.0v4.10v4.11+2 more2023-09-24
CVE-2023-1260 [HIGH] CWE-288 CVE-2023-1260: An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a re
An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already have access to. This might allow eva
nvd
CVE-2023-4853P3HIGHCVSS 8.1v4.10v4.11+1 more2023-09-20
CVE-2023-4853 [HIGH] CWE-148 CVE-2023-4853: A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permut
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and possibly a denial of service.
nvd
CVE-2023-2585P3HIGHCVSS 8.1v4.11v4.122023-12-21
CVE-2023-2585 [HIGH] CWE-358 CVE-2023-2585: Keycloak's device authorization grant does not correctly validate the device code and client ID. An
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
nvd
CVE-2018-18397P4MEDIUMCVSS 5.5PoCv3.112018-12-12
CVE-2018-18397 [MEDIUM] CWE-863 CVE-2018-18397: The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certa
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.
nvd
CVE-2026-3833P3HIGHCVSS 7.4v4.02026-04-30
CVE-2026-3833 [HIGH] CWE-178 CVE-2026-3833: A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive compari
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constraints within `excludedSubtrees` or `permittedSubtrees`. A remote attacker can exploit this by crafting a leaf certificate with casing differences in the Subje
nvd
CVE-2026-0966P3HIGHCVSS 8.2v4.02026-03-26
CVE-2026-0966 [HIGH] CWE-124 CVE-2026-0966: A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service w
A flaw was found in libssh. The API function `ssh_get_hexa()` is vulnerable to a denial of service when processing zero-length input. This can be exploited remotely by an attacker during GSSAPI (Generic Security Service Application Program Interface) authentication if the server's logging verbosity is set to `SSH_LOG_PACKET (3)` or higher. Successful ex
nvd
CVE-2026-54100P3HIGHCVSS 8.3≥ 4.0, ≤ 4.22.12026-06-22
CVE-2026-54100 [HIGH] CWE-295 CVE-2026-54100: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platf
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred duri
nvd
CVE-2019-2602P3HIGHCVSS 7.5v3.112019-04-23
CVE-2019-2602 [HIGH] CWE-400 CVE-2019-2602: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries)
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2026-42009P3HIGHCVSS 7.5v4.02026-05-18
CVE-2026-42009 [HIGH] CWE-475 CVE-2026-42009: A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) packet reordering logic. The comparator function, responsible for ordering DTLS packets by sequence numbers, did not correctly handle packets with duplicate sequence numbers. This could lead to unstable packet ordering or undefined beha
nvd
CVE-2024-5037P3HIGHCVSS 7.5v4.02024-06-05
CVE-2024-5037 [HIGH] CWE-290 CVE-2024-5037: A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
nvd
CVE-2020-10696P3HIGHCVSS 8.8v3.112020-03-31
CVE-2020-10696 [HIGH] CWE-22 CVE-2020-10696: A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker t
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
nvd
CVE-2019-16276P3HIGHCVSS 7.5v4.22019-09-30
CVE-2019-16276 [HIGH] CWE-444 CVE-2019-16276: Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
nvd
CVE-2019-16884P3HIGHCVSS 7.5v4.1v4.22019-09-25
CVE-2019-16884 [HIGH] CWE-863 CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor res
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
nvd
CVE-2019-14819P3HIGHCVSS 8.8v3.10v3.112020-01-07
CVE-2019-14819 [HIGH] CWE-266 CVE-2019-14819: A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using C
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
nvd
CVE-2019-1003049P3HIGHCVSS 8.1v3.112019-04-10
CVE-2019-1003049 [HIGH] CVE-2019-1003049: Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication caches.
nvd
CVE-2024-9341P3HIGHCVSS 8.2v4.12v4.13+4 more2024-10-01
CVE-2024-9341 [HIGH] CWE-59 CVE-2024-9341: A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly ha
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attacker
nvd
CVE-2018-1000863P3HIGHCVSS 8.2v3.112018-12-10
CVE-2018-1000863 [HIGH] CWE-22 CVE-2018-1000863: A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in Us
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an improper migration of user record storage formats, potentially preventing the victim from logging into Jenkins.
nvd