Redhat

Openshift Container Platform

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.61%
  • Veröffentlicht 29.08.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:47

The Kubernetes kube-apiserver mistakenly allows access to a cluster-scoped custom resource if the request is made as if the resource were namespaced. Authorizations for the resource accessed in this manner are enforced using roles and role bindings w...

  • EPSS 3.52%
  • Veröffentlicht 29.08.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:48

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes runs tar inside the container to create a tar archive, copies it over the network, and kubectl unpacks it on the user’s ma...

  • EPSS 0.83%
  • Veröffentlicht 29.08.2019 01:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:48

The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use ...

  • EPSS 0.64%
  • Veröffentlicht 28.08.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:19:00

A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages...

  • EPSS 0.14%
  • Veröffentlicht 28.08.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:19:01

Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed users to obtain CSRF tokens without an associated web session ID, resulting in CSRF tokens that did not expire and could be used to bypass CSRF protection for the anonymous user.

  • EPSS 9.48%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the p...

  • EPSS 10.39%
  • Veröffentlicht 13.08.2019 21:15:12
  • Zuletzt bearbeitet 14.01.2025 19:29:55

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS f...

  • EPSS 0.12%
  • Veröffentlicht 02.08.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:35

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this t...

  • EPSS 0.04%
  • Veröffentlicht 31.07.2019 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:57

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts.

  • EPSS 0.04%
  • Veröffentlicht 31.07.2019 13:15:12
  • Zuletzt bearbeitet 21.11.2024 04:18:57

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts.