Redhat

Openshift

163 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Published 30.07.2021 20:15:07
  • Last modified 21.11.2024 06:22:02

It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trust...

  • EPSS 0.04%
  • Published 02.06.2021 14:15:09
  • Last modified 21.11.2024 05:27:28

An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running container which mounts /etc/kubernetes or has local access to the node, to copy this kubeconfig file an...

  • EPSS 0.16%
  • Published 27.05.2021 20:15:08
  • Last modified 21.11.2024 05:11:19

A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects ope...

Exploit
  • EPSS 0.04%
  • Published 24.03.2021 16:15:14
  • Last modified 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and e...

Exploit
  • EPSS 0.04%
  • Published 24.03.2021 16:15:14
  • Last modified 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escala...

  • EPSS 0.15%
  • Published 19.03.2021 21:15:11
  • Last modified 21.11.2024 04:18:41

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions i...

  • EPSS 0.21%
  • Published 16.09.2020 18:15:12
  • Last modified 21.11.2024 04:55:54

A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially ...

  • EPSS 0.41%
  • Published 13.04.2020 13:15:13
  • Last modified 21.11.2024 05:11:19

A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and pote...

  • EPSS 0.04%
  • Published 02.04.2020 20:15:15
  • Last modified 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this f...

  • EPSS 0.04%
  • Published 02.04.2020 20:15:15
  • Last modified 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw ...