CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-0229
- EPSS 0.65%
- Veröffentlicht 26.01.2023 21:18:06
- Zuletzt bearbeitet 01.04.2025 15:15:57
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profi...
CVE-2023-0296
- EPSS 0.32%
- Veröffentlicht 17.01.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 07:36:55
The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks f...
CVE-2022-3259
- EPSS 0.53%
- Veröffentlicht 09.12.2022 18:15:19
- Zuletzt bearbeitet 22.04.2025 21:15:43
Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks.
CVE-2022-3260
- EPSS 0.43%
- Veröffentlicht 08.12.2022 16:15:13
- Zuletzt bearbeitet 23.04.2025 16:15:24
The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks.
CVE-2022-3262
- EPSS 0.72%
- Veröffentlicht 08.12.2022 16:15:13
- Zuletzt bearbeitet 23.04.2025 16:15:24
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality a...
CVE-2013-4253
- EPSS 0.63%
- Veröffentlicht 19.10.2022 18:15:11
- Zuletzt bearbeitet 09.05.2025 16:15:20
The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.
CVE-2013-4281
- EPSS 0.2%
- Veröffentlicht 19.10.2022 18:15:11
- Zuletzt bearbeitet 09.05.2025 15:15:48
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
CVE-2017-7517
- EPSS 0.48%
- Veröffentlicht 17.10.2022 16:15:14
- Zuletzt bearbeitet 13.05.2025 21:15:58
An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then...
CVE-2022-2403
- EPSS 0.48%
- Veröffentlicht 01.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:00:55
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account....