CVE-2021-3560
- EPSS 13.22%
- Published 16.02.2022 19:15:08
- Last modified 03.04.2025 16:08:28
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new loc...
CVE-2022-0532
- EPSS 0.08%
- Published 09.02.2022 23:15:16
- Last modified 21.11.2024 06:38:51
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork...
CVE-2021-4104
- EPSS 72.2%
- Published 14.12.2021 12:15:12
- Last modified 21.11.2024 06:36:54
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...
CVE-2021-3529
- EPSS 0.23%
- Published 02.06.2021 17:15:08
- Last modified 21.11.2024 06:21:46
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in th...
CVE-2020-14336
- EPSS 0.33%
- Published 02.06.2021 12:15:08
- Last modified 21.11.2024 05:03:02
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deplo...
CVE-2020-10743
- EPSS 0.13%
- Published 02.06.2021 11:15:07
- Last modified 21.11.2024 04:55:58
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in...
CVE-2021-20297
- EPSS 0.1%
- Published 26.05.2021 21:15:08
- Last modified 21.11.2024 05:46:18
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
CVE-2020-27833
- EPSS 0.13%
- Published 14.05.2021 21:15:07
- Last modified 21.11.2024 05:21:54
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command...
CVE-2021-20291
- EPSS 0.11%
- Published 01.04.2021 18:15:12
- Last modified 21.11.2024 05:46:17
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading...
- EPSS 0.04%
- Published 24.03.2021 17:15:12
- Last modified 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privile...