Redhat

Openshift

163 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Published 15.10.2014 14:55:07
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.

  • EPSS 0.25%
  • Published 15.10.2014 14:55:07
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 5.74%
  • Published 20.06.2014 14:55:07
  • Last modified 12.04.2025 10:46:40

cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in...

  • EPSS 0.04%
  • Published 05.05.2014 17:06:05
  • Last modified 12.04.2025 10:46:40

openshift-origin-broker-util, as used in Red Hat OpenShift Enterprise 1.2.7 and 2.0.5, uses world-readable permissions for the mcollective client.cfg configuration file, which allows local users to obtain credentials and other sensitive information b...

  • EPSS 0.38%
  • Published 24.04.2014 14:55:04
  • Last modified 12.04.2025 10:46:40

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary ...

  • EPSS 0.6%
  • Published 08.02.2014 00:55:06
  • Last modified 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF q...

  • EPSS 0.06%
  • Published 03.01.2014 18:54:11
  • Last modified 11.04.2025 00:51:21

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tm...

  • EPSS 88.53%
  • Published 28.10.2013 21:55:05
  • Last modified 11.04.2025 00:51:21

The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name i...

  • EPSS 0.06%
  • Published 24.02.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including...

  • EPSS 0.06%
  • Published 24.02.2013 22:55:01
  • Last modified 11.04.2025 00:51:21

The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.