- EPSS 0.04%
- Veröffentlicht 02.04.2020 20:15:15
- Zuletzt bearbeitet 21.11.2024 04:34:37
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw ...
CVE-2019-19345
- EPSS 0.04%
- Veröffentlicht 20.03.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 04:34:37
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container ...
- EPSS 0.04%
- Veröffentlicht 20.03.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:12
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the containe...
CVE-2020-1709
- EPSS 0.04%
- Veröffentlicht 20.03.2020 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:11:12
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this fla...
- EPSS 0.11%
- Veröffentlicht 18.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:37
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the...
- EPSS 0.11%
- Veröffentlicht 18.03.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:38
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific...
CVE-2019-19335
- EPSS 0.1%
- Veröffentlicht 18.03.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:34:35
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, a...
CVE-2012-6685
- EPSS 0.32%
- Veröffentlicht 19.02.2020 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:46:40
Nokogiri before 1.5.4 is vulnerable to XXE attacks
CVE-2014-0234
- EPSS 8.81%
- Veröffentlicht 12.02.2020 01:15:10
- Zuletzt bearbeitet 21.11.2024 02:01:43
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in...
- EPSS 22.01%
- Veröffentlicht 28.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 01:50:57
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.