Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Published 06.06.2023 20:15:12
  • Last modified 07.01.2025 22:15:29

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large ...

  • EPSS 0.09%
  • Published 10.04.2023 22:15:09
  • Last modified 23.04.2025 17:16:28

A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath f...

  • EPSS 0.67%
  • Published 29.03.2023 21:15:07
  • Last modified 21.11.2024 06:40:23

A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.

  • EPSS 0.04%
  • Published 24.03.2023 20:15:08
  • Last modified 21.11.2024 06:22:09

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pul...

  • EPSS 0.15%
  • Published 23.03.2023 21:15:19
  • Last modified 25.02.2025 20:15:31

An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impac...

Exploit
  • EPSS 0.12%
  • Published 03.03.2023 19:15:11
  • Last modified 06.12.2024 14:15:19

runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to ru...

  • EPSS 0.16%
  • Published 28.12.2022 17:15:09
  • Last modified 21.11.2024 06:37:20

A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch...

Exploit
  • EPSS 0.04%
  • Published 13.09.2022 14:15:08
  • Last modified 05.06.2025 19:15:23

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups ar...

Exploit
  • EPSS 0.13%
  • Published 13.09.2022 14:15:08
  • Last modified 21.11.2024 07:02:02

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups a...

  • EPSS 0.23%
  • Published 01.09.2022 21:15:09
  • Last modified 21.11.2024 06:41:14

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname...