Redhat

Openshift

164 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Veröffentlicht 19.02.2025 18:15:23
  • Zuletzt bearbeitet 11.11.2025 17:15:37

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to overwrite grub2'...

Exploit
  • EPSS 19.14%
  • Veröffentlicht 14.01.2025 18:15:25
  • Zuletzt bearbeitet 14.04.2026 22:16:24

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of un...

  • EPSS 0.1%
  • Veröffentlicht 31.12.2024 15:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/...

  • EPSS 0.37%
  • Veröffentlicht 31.12.2024 03:15:05
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary...

  • EPSS 0.18%
  • Veröffentlicht 19.12.2024 15:15:07
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service accoun...

  • EPSS 0.07%
  • Veröffentlicht 21.11.2024 21:15:23
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

  • EPSS 0.12%
  • Veröffentlicht 17.09.2024 00:15:52
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, al...

  • EPSS 0.99%
  • Veröffentlicht 21.08.2024 06:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficie...

  • EPSS 0.08%
  • Veröffentlicht 09.07.2024 20:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager would crash, leading to a denia...

  • EPSS 0.03%
  • Veröffentlicht 01.05.2024 00:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. An attacker controll...