Redhat

Openshift

164 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 02.04.2020 20:15:15
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw ...

  • EPSS 0.04%
  • Veröffentlicht 20.03.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 04:34:37

A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container ...

  • EPSS 0.04%
  • Veröffentlicht 20.03.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:12

A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the containe...

  • EPSS 0.04%
  • Veröffentlicht 20.03.2020 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:12

A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this fla...

  • EPSS 0.11%
  • Veröffentlicht 18.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:37

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the...

  • EPSS 0.11%
  • Veröffentlicht 18.03.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:38

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific...

  • EPSS 0.1%
  • Veröffentlicht 18.03.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:34:35

During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, a...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 19.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:46:40

Nokogiri before 1.5.4 is vulnerable to XXE attacks

Exploit
  • EPSS 8.81%
  • Veröffentlicht 12.02.2020 01:15:10
  • Zuletzt bearbeitet 21.11.2024 02:01:43

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in...

Exploit
  • EPSS 22.01%
  • Veröffentlicht 28.01.2020 16:15:11
  • Zuletzt bearbeitet 21.11.2024 01:50:57

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.