Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 29.07.2020 18:15:14
  • Last modified 21.11.2024 05:06:03

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB imag...

  • EPSS 0.06%
  • Published 29.07.2020 18:15:14
  • Last modified 21.11.2024 05:06:03

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure b...

Exploit
  • EPSS 0.04%
  • Published 29.07.2020 18:15:14
  • Last modified 21.11.2024 05:06:04

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffe...

  • EPSS 0.14%
  • Published 13.07.2020 21:15:14
  • Last modified 21.11.2024 05:02:57

The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malic...

  • EPSS 0.37%
  • Published 12.06.2020 23:15:10
  • Last modified 21.11.2024 04:55:59

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the ...

  • EPSS 1.14%
  • Published 03.06.2020 18:15:22
  • Last modified 21.11.2024 05:36:29

Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead t...

  • EPSS 3.6%
  • Published 03.06.2020 14:15:12
  • Last modified 21.11.2024 04:55:59

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending...

  • EPSS 0.02%
  • Published 12.05.2020 14:15:12
  • Last modified 21.11.2024 04:55:53

A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluste...

  • EPSS 0.24%
  • Published 24.04.2020 19:15:12
  • Last modified 21.11.2024 05:11:17

A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and th...

  • EPSS 0.29%
  • Published 23.04.2020 15:15:14
  • Last modified 21.11.2024 05:11:19

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.