Redhat

Openshift Container Platform

348 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 22.06.2026 12:46:04
  • Zuletzt bearbeitet 09.09.2026 13:20:30

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additiona...

Exploit
  • EPSS 0.78%
  • Veröffentlicht 11.06.2026 15:33:12
  • Zuletzt bearbeitet 11.09.2026 13:18:08

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...

  • EPSS 0.19%
  • Veröffentlicht 02.06.2026 07:22:26
  • Zuletzt bearbeitet 01.10.2026 17:17:22

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injectio...

  • EPSS 0.23%
  • Veröffentlicht 01.06.2026 13:19:29
  • Zuletzt bearbeitet 22.07.2026 07:10:00

A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit ...

  • EPSS 0.26%
  • Veröffentlicht 29.05.2026 09:50:44
  • Zuletzt bearbeitet 01.10.2026 17:17:24

A flaw was found in the OpenShift Router. A user with EndpointSlice write access can exploit this vulnerability by creating a Service backed by an FQDN (Fully Qualified Domain Name) EndpointSlice that resolves to a cloud metadata endpoint. This allow...

  • EPSS 0.35%
  • Veröffentlicht 29.05.2026 09:50:44
  • Zuletzt bearbeitet 10.09.2026 13:20:19

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP req...

  • EPSS 2.5%
  • Veröffentlicht 28.05.2026 07:25:27
  • Zuletzt bearbeitet 18.09.2026 13:18:31

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client...

  • EPSS 0.86%
  • Veröffentlicht 27.05.2026 12:28:44
  • Zuletzt bearbeitet 18.09.2026 13:17:25

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete reparse point m...

  • EPSS 0.94%
  • Veröffentlicht 27.05.2026 12:09:32
  • Zuletzt bearbeitet 01.10.2026 18:17:17

A flaw was found in Samba’s vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an...

  • EPSS 0.26%
  • Veröffentlicht 27.05.2026 10:02:21
  • Zuletzt bearbeitet 01.10.2026 17:17:23

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without prop...