CVE-2018-10885
- EPSS 0.38%
- Veröffentlicht 05.07.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:13
In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9, ...
CVE-2018-1257
- EPSS 1.79%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:28
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A ...
CVE-2017-2611
- EPSS 0.29%
- Veröffentlicht 08.05.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:49
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jen...
CVE-2018-1102
- EPSS 1.33%
- Veröffentlicht 30.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:11
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
CVE-2018-1059
- EPSS 0.26%
- Veröffentlicht 24.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:05
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing v...
CVE-2016-9592
- EPSS 0.32%
- Veröffentlicht 16.04.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:28
openshift before versions 3.3.1.11, 3.2.1.23, 3.4 is vulnerable to a flaw when a volume fails to detach, which causes the delete operation to fail with 'VolumeInUse' error. Since the delete operation is retried every 30 seconds for each volume, this ...
CVE-2017-7534
- EPSS 0.17%
- Veröffentlicht 11.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:06
OpenShift Enterprise version 3.x is vulnerable to a stored XSS via the log viewer for pods. The flaw is due to lack of sanitation of user input, specifically terminal escape characters, and the creation of clickable links automatically when viewing t...
CVE-2018-1069
- EPSS 0.09%
- Veröffentlicht 09.03.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:06
Red Hat OpenShift Enterprise version 3.7 is vulnerable to access control override for container network filesystems. An attacker could override the UserId and GroupId for GlusterFS and NFS to read and write any data on the network filesystem.
CVE-2013-4364
- EPSS 0.03%
- Veröffentlicht 08.01.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 01:55:25
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
- EPSS 71.46%
- Veröffentlicht 09.11.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x...