Redhat

Openshift

179 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 01.10.2026 09:17:53
  • Zuletzt bearbeitet 07.10.2026 15:17:59

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an ad...

  • EPSS 0.36%
  • Veröffentlicht 23.09.2026 21:24:01
  • Zuletzt bearbeitet 01.10.2026 17:17:31

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive...

  • EPSS 0.25%
  • Veröffentlicht 23.09.2026 20:48:13
  • Zuletzt bearbeitet 01.10.2026 17:17:31

A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token` cookie. This allows the attacker t...

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 21.09.2026 14:05:10
  • Zuletzt bearbeitet 24.09.2026 14:18:16

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. ...

Medienbericht
  • EPSS 0.11%
  • Veröffentlicht 02.09.2026 15:05:33
  • Zuletzt bearbeitet 05.09.2026 14:17:23

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credential...

  • EPSS 0.43%
  • Veröffentlicht 01.09.2026 15:30:57
  • Zuletzt bearbeitet 07.10.2026 15:17:21

A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to golang.org/x/text/language.ParseAcceptLanguage() without input validation. A bypass of the CVE-2022-32149 mitigati...

  • EPSS 0.26%
  • Veröffentlicht 07.08.2026 10:33:33
  • Zuletzt bearbeitet 02.10.2026 00:17:01

A flaw was found in dracut. The die() error-handling function writes its message into a shell script under the initramfs emergency-hook directory without properly shell-quoting it. When the message contains data derived from the DHCP ROOT_PATH option...

  • EPSS 0.08%
  • Veröffentlicht 07.08.2026 07:21:55
  • Zuletzt bearbeitet 01.09.2026 13:18:12

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files un...

  • EPSS 0.13%
  • Veröffentlicht 05.08.2026 14:40:45
  • Zuletzt bearbeitet 06.08.2026 15:37:22

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identity headers (X-Forwarded-User, X-Forwarded-Email, X-Forwarded-Access-Token) to the upstream application...

  • EPSS 0.52%
  • Veröffentlicht 30.07.2026 16:17:14
  • Zuletzt bearbeitet 31.07.2026 23:17:25

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and at...