Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.67%
  • Published 15.10.2024 16:15:06
  • Last modified 03.04.2025 02:15:19

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...

  • EPSS 0.08%
  • Published 09.10.2024 15:15:17
  • Last modified 25.08.2025 02:11:05

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/w...

  • EPSS 0.46%
  • Published 01.10.2024 19:15:09
  • Last modified 11.12.2024 04:15:06

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and tri...

  • EPSS 4.89%
  • Published 19.09.2024 16:15:06
  • Last modified 26.11.2024 19:15:32

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes...

  • EPSS 0.17%
  • Published 03.09.2024 20:15:09
  • Last modified 21.11.2024 09:43:14

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed...

  • EPSS 0.47%
  • Published 02.08.2024 21:16:30
  • Last modified 27.12.2024 16:15:24

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious ...

  • EPSS 0.33%
  • Published 24.07.2024 16:15:07
  • Last modified 21.11.2024 09:50:50

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middl...

Media report Exploit
  • EPSS 38.58%
  • Published 01.07.2024 13:15:06
  • Last modified 30.09.2025 13:52:23

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...

  • EPSS 1.26%
  • Published 12.06.2024 09:15:19
  • Last modified 23.06.2025 14:15:26

A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system.

  • EPSS 0.19%
  • Published 05.06.2024 18:15:11
  • Last modified 21.11.2024 09:46:49

A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.