CVE-2024-12698
- EPSS 0.48%
- Veröffentlicht 18.12.2024 05:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created by authenticated sources.
CVE-2024-6538
- EPSS 0.57%
- Veröffentlicht 25.11.2024 07:15:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exp...
CVE-2024-0793
- EPSS 0.6%
- Veröffentlicht 17.11.2024 11:15:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
CVE-2024-11217
- EPSS 0.36%
- Veröffentlicht 15.11.2024 21:15:06
- Zuletzt bearbeitet 26.06.2026 05:16:25
A vulnerability was found in the OAuth-server. OAuth-server logs the OAuth2 client secret when the logLevel is Debug higher for OIDC/GitHub/GitLab/Google IDPs login options.
CVE-2024-50311
- EPSS 0.6%
- Veröffentlicht 22.10.2024 14:15:19
- Zuletzt bearbeitet 25.02.2025 08:15:29
A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to subm...
CVE-2024-50312
- EPSS 0.56%
- Veröffentlicht 22.10.2024 14:15:19
- Zuletzt bearbeitet 11.08.2026 16:17:21
A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the atta...
CVE-2024-9676
- EPSS 1.34%
- Veröffentlicht 15.10.2024 16:15:06
- Zuletzt bearbeitet 19.03.2026 18:16:13
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...
CVE-2024-9675
- EPSS 0.39%
- Veröffentlicht 09.10.2024 15:15:17
- Zuletzt bearbeitet 07.08.2026 14:16:51
A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/w...
CVE-2024-9341
- EPSS 0.97%
- Veröffentlicht 01.10.2024 19:15:09
- Zuletzt bearbeitet 11.08.2026 16:17:25
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and tri...
CVE-2024-8883
- EPSS 1.96%
- Veröffentlicht 19.09.2024 16:15:06
- Zuletzt bearbeitet 04.08.2026 11:22:41
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes...