Redhat

Openshift Container Platform

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 22.10.2024 14:15:19
  • Zuletzt bearbeitet 25.02.2025 08:15:29

A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to subm...

  • EPSS 0.19%
  • Veröffentlicht 22.10.2024 14:15:19
  • Zuletzt bearbeitet 15.01.2025 02:15:26

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the atta...

  • EPSS 1.33%
  • Veröffentlicht 15.10.2024 16:15:06
  • Zuletzt bearbeitet 03.04.2025 02:15:19

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...

  • EPSS 0.13%
  • Veröffentlicht 09.10.2024 15:15:17
  • Zuletzt bearbeitet 25.08.2025 02:11:05

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/w...

  • EPSS 0.97%
  • Veröffentlicht 01.10.2024 19:15:09
  • Zuletzt bearbeitet 11.12.2024 04:15:06

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and tri...

  • EPSS 4.47%
  • Veröffentlicht 19.09.2024 16:15:06
  • Zuletzt bearbeitet 26.11.2024 19:15:32

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes...

  • EPSS 0.33%
  • Veröffentlicht 03.09.2024 20:15:09
  • Zuletzt bearbeitet 21.11.2024 09:43:14

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed...

  • EPSS 0.47%
  • Veröffentlicht 02.08.2024 21:16:30
  • Zuletzt bearbeitet 27.12.2024 16:15:24

A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious ...

  • EPSS 0.33%
  • Veröffentlicht 24.07.2024 16:15:07
  • Zuletzt bearbeitet 21.11.2024 09:50:50

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middl...

Medienbericht Exploit
  • EPSS 54.14%
  • Veröffentlicht 01.07.2024 13:15:06
  • Zuletzt bearbeitet 30.09.2025 13:52:23

A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to aut...