Redhat

Openshift

179 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Veröffentlicht 28.07.2026 12:18:26
  • Zuletzt bearbeitet 21.09.2026 17:17:35

A flaw was found in openshift/oauth-proxy. The proxy sets authenticated identity headers using only dash-variant keys (X-Forwarded-User) but does not strip underscore-variant keys (X_Forwarded_User) from incoming requests. WSGI and PHP frameworks nor...

  • EPSS 0.11%
  • Veröffentlicht 24.07.2026 11:26:18
  • Zuletzt bearbeitet 10.09.2026 18:17:56

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open many connection...

  • EPSS 0.27%
  • Veröffentlicht 20.07.2026 10:36:03
  • Zuletzt bearbeitet 21.08.2026 13:16:53

A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does not properly validate sequence numbers of incoming payload fragments. An attacker can exploit this lack...

  • EPSS 0.16%
  • Veröffentlicht 12.06.2026 09:42:36
  • Zuletzt bearbeitet 31.08.2026 18:17:17

A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of input descriptors before writing data. A malicious guest with high privileges could exploit this vulnerability by submitting a ma...

  • EPSS 0.33%
  • Veröffentlicht 04.06.2026 12:04:49
  • Zuletzt bearbeitet 22.07.2026 20:10:00

A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-s...

  • EPSS 0.18%
  • Veröffentlicht 28.04.2026 12:33:55
  • Zuletzt bearbeitet 07.05.2026 02:16:00

A flaw was found in the OpenShift Container Platform build system. A user with the `edit` ClusterRole can inject arbitrary environment variables, such as `LD_PRELOAD` or `http_proxy`, into `docker-build` containers through the `buildconfigs/instantia...

Exploit
  • EPSS 0.99%
  • Veröffentlicht 01.04.2026 13:18:55
  • Zuletzt bearbeitet 21.08.2026 13:17:37

A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading ...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 01.04.2026 13:18:53
  • Zuletzt bearbeitet 21.08.2026 13:17:36

A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to a...

  • EPSS 0.59%
  • Veröffentlicht 11.12.2025 07:16:00
  • Zuletzt bearbeitet 07.10.2026 11:10:00

A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribu...

  • EPSS 1.08%
  • Veröffentlicht 05.09.2025 19:54:30
  • Zuletzt bearbeitet 28.09.2026 02:17:17

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In a successful...