Redhat

Openshift

163 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.07%
  • Published 19.10.2022 18:15:11
  • Last modified 09.05.2025 16:15:20

The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

  • EPSS 0.03%
  • Published 19.10.2022 18:15:11
  • Last modified 09.05.2025 15:15:48

In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

  • EPSS 0.24%
  • Published 17.10.2022 16:15:14
  • Last modified 13.05.2025 21:15:58

An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then...

  • EPSS 0.86%
  • Published 01.09.2022 21:15:09
  • Last modified 21.11.2024 07:00:55

A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account....

  • EPSS 1.14%
  • Published 24.08.2022 16:15:09
  • Last modified 21.11.2024 06:36:57

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container im...

  • EPSS 0.06%
  • Published 06.07.2022 16:15:08
  • Last modified 21.11.2024 06:22:10

A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...

  • EPSS 0.11%
  • Published 06.07.2022 16:15:08
  • Last modified 21.11.2024 06:22:10

A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an atta...

  • EPSS 0.07%
  • Published 06.07.2022 16:15:08
  • Last modified 21.11.2024 06:22:10

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a...

Exploit
  • EPSS 0.31%
  • Published 30.06.2022 19:15:08
  • Last modified 21.11.2024 01:55:50

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

  • EPSS 0.2%
  • Published 11.04.2022 20:15:16
  • Last modified 21.11.2024 06:36:47

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.