CVE-2021-3529
- EPSS 0.23%
- Veröffentlicht 02.06.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:21:46
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in th...
CVE-2020-14336
- EPSS 0.33%
- Veröffentlicht 02.06.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:03:02
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deplo...
CVE-2020-10743
- EPSS 0.13%
- Veröffentlicht 02.06.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:58
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary actions in...
CVE-2021-20297
- EPSS 0.1%
- Veröffentlicht 26.05.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:18
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
CVE-2020-27833
- EPSS 0.1%
- Veröffentlicht 14.05.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:54
A Zip Slip vulnerability was found in the oc binary in openshift-clients where an arbitrary file write is achieved by using a specially crafted raw container image (.tar file) which contains symbolic links. The vulnerability is limited to the command...
CVE-2021-20291
- EPSS 1.03%
- Veröffentlicht 01.04.2021 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:46:17
A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading...
- EPSS 0.04%
- Veröffentlicht 24.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privile...
- EPSS 0.04%
- Veröffentlicht 24.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privilege...
CVE-2019-19354
- EPSS 0.05%
- Veröffentlicht 24.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privile...
CVE-2021-20270
- EPSS 0.21%
- Veröffentlicht 23.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:15
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.