Redhat

Openshift Dev Spaces

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 18.09.2026 16:44:09
  • Zuletzt bearbeitet 18.09.2026 19:06:08

A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authentica...

  • EPSS 0.33%
  • Veröffentlicht 18.09.2026 16:43:51
  • Zuletzt bearbeitet 22.09.2026 17:17:28

A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact U...

  • EPSS 0.35%
  • Veröffentlicht 18.09.2026 16:43:46
  • Zuletzt bearbeitet 30.09.2026 22:16:34

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detac...

  • EPSS 0.36%
  • Veröffentlicht 19.08.2026 12:44:55
  • Zuletzt bearbeitet 25.08.2026 03:16:58

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial...

  • EPSS 0.29%
  • Veröffentlicht 29.06.2026 12:33:52
  • Zuletzt bearbeitet 15.07.2026 02:18:11

A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in JavaDoc hovers, allowing a malicious Java file to include hidden commands. If a user ...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 11.06.2026 15:33:12
  • Zuletzt bearbeitet 11.09.2026 13:18:08

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...

  • EPSS 0.38%
  • Veröffentlicht 26.01.2026 19:36:40
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in Hibernate Reactive. When an HTTP endpoint is exposed to perform database operations, a remote client can prematurely close the HTTP connection. This action may lead to leaking connections from the database connection pool, potenti...

  • EPSS 1.18%
  • Veröffentlicht 13.01.2026 15:35:01
  • Zuletzt bearbeitet 21.09.2026 17:17:24

A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command execution and secret exfiltration (SSH keys, tokens, etc.) from other users' Developer Workspace containers, via an unauthenticated J...

  • EPSS 0.18%
  • Veröffentlicht 02.12.2025 18:53:35
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute com...

  • EPSS 1.08%
  • Veröffentlicht 05.09.2025 19:54:30
  • Zuletzt bearbeitet 28.09.2026 02:17:17

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...