- EPSS 0.04%
- Veröffentlicht 24.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privilege...
CVE-2019-19354
- EPSS 0.05%
- Veröffentlicht 24.03.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privile...
CVE-2021-20270
- EPSS 0.12%
- Veröffentlicht 23.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:15
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
- EPSS 0.39%
- Veröffentlicht 19.03.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:38
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can ret...
CVE-2019-10225
- EPSS 0.15%
- Veröffentlicht 19.03.2021 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:41
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions i...
CVE-2020-27827
- EPSS 0.42%
- Veröffentlicht 18.03.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:53
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerabilit...
CVE-2021-3344
- EPSS 0.68%
- Veröffentlicht 16.03.2021 22:15:11
- Zuletzt bearbeitet 21.11.2024 06:21:20
A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time insi...
CVE-2021-20218
- EPSS 0.59%
- Veröffentlicht 16.03.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:46:09
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest t...
CVE-2020-25639
- EPSS 0.13%
- Veröffentlicht 04.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:18:18
A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system.
CVE-2021-20194
- EPSS 0.05%
- Veröffentlicht 23.02.2021 23:15:13
- Zuletzt bearbeitet 21.11.2024 05:46:06
There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt i...