cbcvebase.

Redhat Openshift Container Platform vulnerabilities

296 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
296
CISA KEV
8
actively exploited
Public exploits
23
Exploited in wild
8
Severity breakdown
CRITICAL38HIGH133MEDIUM118LOW7

Vulnerabilities

Page 6 of 15
CVE-2023-27561HIGHCVSS 7.0v4.02023-03-03
CVE-2023-27561 [HIGH] CVE-2023-27561: runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libc runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
nvd
CVE-2021-4294MEDIUMCVSS 5.9v4.02022-12-28
CVE-2021-4294 [MEDIUM] CWE-208 CVE-2021-4294: A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to apply a patch to fix this issue. The
nvd
CVE-2022-2989HIGHCVSS 7.1v3.11v4.02022-09-13
CVE-2022-2989 [HIGH] CWE-842 CVE-2022-2989: An incorrect handling of the supplementary groups in the Podman container engine might lead to the s An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2022-2990HIGHCVSS 7.1v4.02022-09-13
CVE-2022-2990 [HIGH] CWE-842 CVE-2022-2990: An incorrect handling of the supplementary groups in the Buildah container engine might lead to the An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
nvd
CVE-2022-1632MEDIUMCVSS 6.5v4.0v4.8.172022-09-01
CVE-2022-1632 [MEDIUM] CWE-295 CVE-2022-1632: An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinatio An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
nvd
CVE-2022-1677MEDIUMCVSS 6.3v3.11v4.6+5 more2022-09-01
CVE-2022-1677 [MEDIUM] CWE-400 CVE-2022-1677: In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payl In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, i
nvd
CVE-2022-2132HIGHCVSS 8.6v4.02022-08-31
CVE-2022-2132 [HIGH] CWE-791 CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to c A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
nvd
CVE-2022-0669MEDIUMCVSS 6.5v4.02022-08-29
CVE-2022-0669 [MEDIUM] CWE-400 CVE-2022-0669: A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected num A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave proc
nvd
CVE-2022-0718MEDIUMCVSS 4.9v4.02022-08-29
CVE-2022-0718 [MEDIUM] CWE-522 CVE-2022-0718: A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
nvd
CVE-2021-3669MEDIUMCVSS 5.5v4.6v4.7+1 more2022-08-26
CVE-2021-3669 [MEDIUM] CWE-400 CVE-2021-3669: A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
nvd
CVE-2021-3827MEDIUMCVSS 6.8v4.8v4.92022-08-23
CVE-2021-3827 [MEDIUM] CWE-287 CVE-2021-3827: A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows t A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiali
nvd
CVE-2020-27836CRITICALCVSS 9.8v4.62022-08-22
CVE-2020-27836 [CRITICAL] CWE-732 CVE-2020-27836: A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability..
nvd
CVE-2021-3697HIGHCVSS 7.0v4.6v4.9+1 more2022-07-06
CVE-2021-3697 [HIGH] CWE-787 CVE-2021-3697: A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlle A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data corruption and eventual code execution
nvd
CVE-2021-3695MEDIUMCVSS 4.5v4.6v4.9+1 more2022-07-06
CVE-2021-3695 [MEDIUM] CWE-787 CVE-2021-3695: A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform some triage over the heap layout to
nvd
CVE-2021-3696MEDIUMCVSS 4.5v4.6v4.9+1 more2022-07-06
CVE-2021-3696 [MEDIUM] CWE-787 CVE-2021-3696: A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman entries to achieve results such as arbitr
nvd
CVE-2022-1708HIGHCVSS 7.5v3.11v4.0+2 more2022-06-07
CVE-2022-1708 [HIGH] CWE-400 CVE-2022-1708: A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyon A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of
nvd
CVE-2022-1706MEDIUMCVSS 6.5v4.02022-05-17
CVE-2022-1706 [MEDIUM] CWE-863 CVE-2022-1706: A vulnerability was found in Ignition where ignition configs are accessible from unprivileged contai A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the
nvd
CVE-2022-1227HIGHCVSS 8.8v4.02022-04-29
CVE-2022-1227 [HIGH] CWE-281 CVE-2022-1227: A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or
nvd
CVE-2022-27652MEDIUMCVSS 5.3v3.11v4.02022-04-18
CVE-2022-27652 [MEDIUM] CWE-276 CVE-2022-27652: A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissi A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those
nvd
CVE-2022-27650HIGHCVSS 7.5v4.02022-04-04
CVE-2022-27650 [HIGH] CWE-276 CVE-2022-27650: A flaw was found in crun where containers were incorrectly started with non-empty default permission A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate thos
nvd