cbcvebase.

Redhat Openshift Container Platform vulnerabilities

312 known vulnerabilities affecting redhat/openshift_container_platform.

Total CVEs
312
CISA KEV
8
actively exploited
Public exploits
24
Exploited in wild
17
Severity breakdown
CRITICAL39HIGH138MEDIUM126LOW9

Vulnerabilities

Page 8 of 16
CVE-2018-12910P3CRITICALCVSS 9.8v3.112018-07-05
CVE-2018-12910 [CRITICAL] CWE-125 CVE-2018-12910: The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
nvd
CVE-2019-1003011P3HIGHCVSS 8.1v3.112019-02-06
CVE-2019-1003011 [HIGH] CWE-674 CVE-2019-1003011: An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 An information exposure and denial of service vulnerability exists in Jenkins Token Macro Plugin 2.5 and earlier in src/main/java/org/jenkinsci/plugins/tokenmacro/Parser.java, src/main/java/org/jenkinsci/plugins/tokenmacro/TokenMacro.java, src/main/java/org/jenkinsci/plugins/tokenmacro/impl/AbstractChangesSinceMacro.java, src/main/java/org/jenkins
nvd
CVE-2020-10712P3HIGHCVSS 8.2≤ 4.12020-04-22
CVE-2020-10712 [HIGH] CWE-532 CVE-2020-10712: A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was fo A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is to data integrity.
nvd
CVE-2024-0406P3HIGHCVSS 7.8≥ 4.18, < 4.18.42024-04-06
CVE-2024-0406 [HIGH] CWE-22 CVE-2024-0406: A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specia A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
nvd
CVE-2019-7221P3HIGHCVSS 7.8v3.112019-03-21
CVE-2019-7221 [HIGH] CWE-416 CVE-2019-7221: The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
nvd
CVE-2018-20103P3HIGHCVSS 7.5v3.112018-12-12
CVE-2018-20103 [HIGH] CWE-835 CVE-2018-20103: An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a c An issue was discovered in dns.c in HAProxy through 1.8.14. In the case of a compressed pointer, a crafted packet can trigger infinite recursion by making the pointer point to itself, or create a long chain of valid pointers resulting in stack exhaustion.
nvd
CVE-2022-3248P3HIGHCVSS 7.5v4.02023-10-05
CVE-2022-3248 [HIGH] CWE-863 CVE-2022-3248: A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. Thi A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.
nvd
CVE-2022-3916P3MEDIUMCVSS 6.8v4.9v4.102023-09-20
CVE-2022-3916 [MEDIUM] CWE-384 CVE-2022-3916: A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared co A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authen
nvd
CVE-2020-27827P3HIGHCVSS 7.5v4.02021-03-18
CVE-2020-27827 [HIGH] CWE-400 CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memor A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2023-6563P3HIGHCVSS 7.7v4.11v4.122023-12-14
CVE-2023-6563 [HIGH] CWE-770 CVE-2023-6563: An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge
nvd
CVE-2025-7424P3HIGHCVSS 7.5v4.02025-07-10
CVE-2025-7424 [HIGH] CWE-843 CVE-2025-7424: A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet an A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application or corrupt memory. In some cases, it may lead to denial of service or unexpected behavior.
nvd
CVE-2021-20194P3HIGHCVSS 7.8v4.4v4.5+1 more2021-02-23
CVE-2021-20194 [HIGH] CWE-20 CVE-2021-20194: There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with confi There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger bug in __cgroup_bpf_run_filter_get
nvd
CVE-2020-10752P3HIGHCVSS 7.5v3.11v4.02020-06-12
CVE-2020-10752 [HIGH] CWE-522 CVE-2020-10752: A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with the leaked token.
nvd
CVE-2026-48864P3HIGHCVSS 7.8v4.02026-05-26
CVE-2026-48864 [HIGH] CWE-787 CVE-2026-48864: A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-c A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, when processed by a vulnerable application, can lead to out-of-bounds memory access. This could result
nvd
CVE-2019-1003003P3HIGHCVSS 7.2v3.112019-01-22
CVE-2019-1003003 [HIGH] CVE-2019-1003003: An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier An improper authorization vulnerability exists in Jenkins 2.158 and earlier, LTS 2.150.1 and earlier in core/src/main/java/hudson/security/TokenBasedRememberMeServices2.java that allows attackers with Overall/RunScripts permission to craft Remember Me cookies that would never expire, allowing e.g. to persist access to temporarily compromised user accounts
nvd
CVE-2023-2422P3HIGHCVSS 7.1v4.9v4.10+2 more2023-10-04
CVE-2023-2422 [HIGH] CWE-295 CVE-2023-2422: A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/ A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
nvd
CVE-2019-10384P3HIGHCVSS 8.8v3.11v4.12019-08-28
CVE-2019-10384 [HIGH] CWE-352 CVE-2019-10384: Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an as Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.
nvd
CVE-2025-12801P3MEDIUMCVSS 6.5v4.02026-03-04
CVE-2025-12801 [MEDIUM] CWE-279 CVE-2025-12801: A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, a
nvd
CVE-2026-42965P3MEDIUMCVSS 6.5v4.02026-05-29
CVE-2026-42965 [MEDIUM] CWE-918 CVE-2026-42965: A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vu A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allows the router to proxy requests to the cloud metadata endpoint, leading to the disclosure of instance
nvd
CVE-2023-1108P3HIGHCVSS 7.5v4.11v4.122023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd
Redhat Openshift Container Platform vulnerabilities | cvebase