Redhat

Openshift

163 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Published 17.05.2016 14:08:05
  • Last modified 12.04.2025 10:46:40

Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.

  • EPSS 0.37%
  • Published 11.04.2016 21:59:09
  • Last modified 12.04.2025 10:46:40

Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.

Exploit
  • EPSS 89.81%
  • Published 07.04.2016 23:59:03
  • Last modified 12.04.2025 10:46:40

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

  • EPSS 0.47%
  • Published 07.04.2016 23:59:02
  • Last modified 12.04.2025 10:46:40

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.

  • EPSS 0.15%
  • Published 07.04.2016 23:59:01
  • Last modified 12.04.2025 10:46:40

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • EPSS 0.21%
  • Published 07.04.2016 23:59:01
  • Last modified 12.04.2025 10:46:40

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.

  • EPSS 37.43%
  • Published 07.04.2016 23:59:00
  • Last modified 12.04.2025 10:46:40

The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

  • EPSS 1.04%
  • Published 03.02.2016 18:59:03
  • Last modified 12.04.2025 10:46:40

The Plugins Manager in Jenkins before 1.640 and LTS before 1.625.2 does not verify checksums for plugin files referenced in update site data, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted plugin.

  • EPSS 0.4%
  • Published 03.02.2016 18:59:02
  • Last modified 12.04.2025 10:46:40

Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method...

  • EPSS 0.23%
  • Published 03.02.2016 18:59:02
  • Last modified 12.04.2025 10:46:40

Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.