Redhat

Openshift

163 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Published 05.09.2025 19:54:30
  • Last modified 23.09.2025 22:15:34

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...

  • EPSS 0.04%
  • Published 20.08.2025 12:19:18
  • Last modified 20.08.2025 14:39:07

There's a vulnerability in the CRI-O application where when container is launched with securityContext.runAsUser specifying a non-existent user, CRI-O attempts to create the user, reading the container's entire /etc/passwd file into memory. If this f...

  • EPSS 0.02%
  • Published 16.06.2025 15:24:05
  • Last modified 12.08.2025 13:04:06

A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow...

  • EPSS 0.08%
  • Published 31.03.2025 12:15:15
  • Last modified 01.04.2025 20:26:30

A flaw was found in the OpenShift Lightspeed Service, which is vulnerable to unauthenticated API request flooding. Repeated queries to non-existent endpoints inflate metrics storage and processing, consuming excessive resources. This issue can lead t...

  • EPSS 0.13%
  • Published 19.03.2025 17:57:14
  • Last modified 19.03.2025 18:15:20

A flaw was found in the Hive hibernation controller component of OpenShift Dedicated. The ClusterDeployment.hive.openshift.io/v1 resource can be created with the spec.installed field set to true, regardless of the installation status, and a positive ...

  • EPSS 0.02%
  • Published 03.03.2025 15:15:16
  • Last modified 12.08.2025 14:15:27

When reading data from disk, the grub's UDF filesystem module utilizes the user controlled data length metadata to allocate its internal buffers. In certain scenarios, while iterating through disk sectors, it assumes the read size from the disk is al...

  • EPSS 0.03%
  • Published 19.02.2025 18:15:23
  • Last modified 28.07.2025 17:26:10

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2'...

Exploit
  • EPSS 9.67%
  • Published 14.01.2025 18:15:25
  • Last modified 12.08.2025 21:15:27

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...

  • EPSS 0.19%
  • Published 31.12.2024 15:15:08
  • Last modified 06.02.2025 09:15:10

A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/...

  • EPSS 0.44%
  • Published 31.12.2024 03:15:05
  • Last modified 17.07.2025 08:15:27

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary...