Redhat

Openshift

163 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 30.07.2021 20:15:07
  • Zuletzt bearbeitet 21.11.2024 06:22:02

It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trust...

  • EPSS 0.04%
  • Veröffentlicht 02.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 05:27:28

An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file an...

  • EPSS 0.16%
  • Veröffentlicht 27.05.2021 20:15:08
  • Zuletzt bearbeitet 21.11.2024 05:11:19

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects ope...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 24.03.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and e...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 24.03.2021 16:15:14
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escala...

  • EPSS 0.15%
  • Veröffentlicht 19.03.2021 21:15:11
  • Zuletzt bearbeitet 21.11.2024 04:18:41

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions i...

  • EPSS 0.21%
  • Veröffentlicht 16.09.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:55:54

A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially ...

  • EPSS 0.41%
  • Veröffentlicht 13.04.2020 13:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:19

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and pote...

  • EPSS 0.04%
  • Veröffentlicht 02.04.2020 20:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this f...

  • EPSS 0.04%
  • Veröffentlicht 02.04.2020 20:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw ...