Redhat

Openshift Container Platform

272 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 13.22%
  • Veröffentlicht 16.02.2022 19:15:08
  • Zuletzt bearbeitet 03.04.2025 16:08:28

It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new loc...

  • EPSS 0.08%
  • Veröffentlicht 09.02.2022 23:15:16
  • Zuletzt bearbeitet 21.11.2024 06:38:51

An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork...

  • EPSS 72.2%
  • Veröffentlicht 14.12.2021 12:15:12
  • Zuletzt bearbeitet 21.11.2024 06:36:54

JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...

  • EPSS 0.23%
  • Veröffentlicht 02.06.2021 17:15:08
  • Zuletzt bearbeitet 21.11.2024 06:21:46

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in th...

  • EPSS 0.33%
  • Veröffentlicht 02.06.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 05:03:02

A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deplo...

  • EPSS 0.13%
  • Veröffentlicht 02.06.2021 11:15:07
  • Zuletzt bearbeitet 21.11.2024 04:55:58

It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in...

  • EPSS 0.1%
  • Veröffentlicht 26.05.2021 21:15:08
  • Zuletzt bearbeitet 21.11.2024 05:46:18

A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.

  • EPSS 0.13%
  • Veröffentlicht 14.05.2021 21:15:07
  • Zuletzt bearbeitet 21.11.2024 05:21:54

A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 01.04.2021 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:46:17

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading...

  • EPSS 0.04%
  • Veröffentlicht 24.03.2021 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:34:38

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privile...