CVE-2014-0188
- EPSS 1.67%
- Veröffentlicht 24.04.2014 14:55:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary ...
CVE-2014-1869
- EPSS 2.79%
- Veröffentlicht 08.02.2014 00:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF q...
CVE-2013-2119
- EPSS 0.4%
- Veröffentlicht 03.01.2014 18:54:11
- Zuletzt bearbeitet 29.04.2026 01:13:23
Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tm...
CVE-2013-2186
- EPSS 12.77%
- Veröffentlicht 28.10.2013 21:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name i...
CVE-2012-5658
- EPSS 0.36%
- Veröffentlicht 24.02.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including...
CVE-2013-0164
- EPSS 0.37%
- Veröffentlicht 24.02.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
CVE-2012-5647
- EPSS 1.47%
- Veröffentlicht 24.02.2013 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.
CVE-2012-5646
- EPSS 2.2%
- Veröffentlicht 24.02.2013 21:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO.
CVE-2012-5622
- EPSS 0.66%
- Veröffentlicht 18.12.2012 01:55:07
- Zuletzt bearbeitet 16.06.2026 23:47:06
Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors...