Redhat

Openshift Container Platform

272 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Published 16.07.2018 20:29:00
  • Last modified 21.11.2024 03:14:08

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.

  • EPSS 5.21%
  • Published 05.07.2018 18:29:00
  • Last modified 21.11.2024 03:46:05

The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.

  • EPSS 0.28%
  • Published 02.07.2018 17:29:00
  • Last modified 21.11.2024 03:42:07

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container....

Exploit
  • EPSS 1.48%
  • Published 01.07.2018 16:29:00
  • Last modified 21.11.2024 03:46:16

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_p...

  • EPSS 1.48%
  • Published 15.06.2018 13:29:01
  • Last modified 21.11.2024 03:59:08

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabled. Quotations around the values of ETCD_CLIENT_CERT_AUTH and ETCD_PEER_CLIENT_CERT_AUTH in etcd.conf...

  • EPSS 0.16%
  • Published 12.06.2018 13:29:00
  • Last modified 21.11.2024 03:59:07

routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for o...

  • EPSS 3.26%
  • Published 26.04.2018 21:29:00
  • Last modified 21.11.2024 03:41:04

Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray...

  • EPSS 7.41%
  • Published 06.02.2018 15:29:00
  • Last modified 21.11.2024 03:14:03

A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMappe...

  • EPSS 77.34%
  • Published 06.02.2018 15:29:00
  • Last modified 21.11.2024 03:32:04

A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the Obj...

  • EPSS 2.12%
  • Published 22.01.2018 04:29:00
  • Last modified 21.11.2024 04:09:46

FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets ...