Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 22.04.2019 15:29:00
  • Last modified 21.11.2024 04:20:47

In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a differe...

  • EPSS 0.42%
  • Published 10.04.2019 21:29:01
  • Last modified 21.11.2024 04:17:48

Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these ...

  • EPSS 0.99%
  • Published 10.04.2019 21:29:01
  • Last modified 21.11.2024 04:17:48

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to c...

Warning Exploit
  • EPSS 85.73%
  • Published 08.04.2019 22:29:00
  • Last modified 04.04.2025 15:34:11

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with...

  • EPSS 0.2%
  • Published 01.04.2019 15:29:01
  • Last modified 21.11.2024 04:42:46

A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via Jav...

  • EPSS 8.65%
  • Published 01.04.2019 14:29:00
  • Last modified 21.11.2024 04:17:42

In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Ty...

  • EPSS 47.33%
  • Published 01.04.2019 14:29:00
  • Last modified 21.11.2024 04:17:42

The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar b...

  • EPSS 2.25%
  • Published 28.03.2019 18:29:00
  • Last modified 21.11.2024 04:17:47

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.

  • EPSS 2.25%
  • Published 28.03.2019 18:29:00
  • Last modified 21.11.2024 04:17:47

A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts.

  • EPSS 2.34%
  • Published 26.03.2019 18:29:00
  • Last modified 21.11.2024 04:42:37

A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowing for the execution and persis...