Redhat

Openshift

179 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 21.11.2024 21:15:23
  • Zuletzt bearbeitet 29.06.2026 23:16:41

A flaw was found in Avahi-daemon, which relies on fixed source ports for wide-area DNS queries. This issue simplifies attacks where malicious DNS responses are injected.

  • EPSS 1.02%
  • Veröffentlicht 17.09.2024 00:15:52
  • Zuletzt bearbeitet 11.08.2026 16:17:18

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, al...

  • EPSS 0.67%
  • Veröffentlicht 21.08.2024 06:15:08
  • Zuletzt bearbeitet 11.08.2026 16:17:22

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficie...

  • EPSS 0.45%
  • Veröffentlicht 09.07.2024 20:15:12
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager would crash, leading to a denia...

  • EPSS 0.69%
  • Veröffentlicht 01.05.2024 00:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An information disclosure flaw was found in OpenShift's internal image registry operator. The AZURE_CLIENT_SECRET can be exposed through an environment variable defined in the pod definition, but is limited to Azure environments. An attacker controll...

  • EPSS 1.42%
  • Veröffentlicht 26.04.2024 04:15:09
  • Zuletzt bearbeitet 24.08.2026 15:16:37

A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.

  • EPSS 0.33%
  • Veröffentlicht 25.04.2024 18:15:08
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A security vulnerability has been discovered within rpm-ostree, pertaining to the /etc/shadow file in default builds having the world-readable bit enabled. This issue arises from the default permissions being set at a higher level than recommended, p...

  • EPSS 0.89%
  • Veröffentlicht 25.04.2024 17:15:47
  • Zuletzt bearbeitet 14.08.2026 07:16:50

A credentials leak vulnerability was found in the cluster monitoring operator in OCP. This issue may allow a remote attacker who has basic login credentials to check the pod manifest to discover a repository pull secret.

  • EPSS 0.79%
  • Veröffentlicht 25.04.2024 16:15:10
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An incomplete fix was shipped for the Rapid Reset (CVE-2023-44487/CVE-2023-39325) vulnerability for an OpenShift Containers.

  • EPSS 0.94%
  • Veröffentlicht 14.02.2024 00:15:46
  • Zuletzt bearbeitet 24.03.2026 12:16:11

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious a...