CVE-2021-20182
- EPSS 0.53%
- Published 23.02.2021 22:15:12
- Last modified 21.11.2024 05:46:05
A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize t...
- EPSS 0.09%
- Published 11.02.2021 18:15:16
- Last modified 21.11.2024 05:46:05
A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container,...
- EPSS 11.9%
- Published 21.12.2020 16:15:13
- Last modified 21.11.2024 05:21:55
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVE-2020-27781
- EPSS 0.04%
- Published 18.12.2020 21:15:12
- Last modified 21.11.2024 05:21:49
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. ...
CVE-2020-27777
- EPSS 0.03%
- Published 15.12.2020 17:15:14
- Last modified 21.11.2024 05:21:48
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use...
CVE-2020-27786
- EPSS 12.25%
- Published 11.12.2020 05:15:12
- Last modified 21.11.2024 05:21:49
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and be...
CVE-2020-27816
- EPSS 0.17%
- Published 02.12.2020 01:15:12
- Last modified 21.11.2024 05:21:52
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR f...
CVE-2020-10763
- EPSS 0.13%
- Published 24.11.2020 17:15:10
- Last modified 21.11.2024 04:56:01
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
CVE-2020-25660
- EPSS 0.27%
- Published 23.11.2020 22:15:12
- Last modified 21.11.2024 05:18:23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the ...
CVE-2020-14370
- EPSS 0.15%
- Published 23.09.2020 13:15:15
- Last modified 21.11.2024 05:03:06
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variable...