- EPSS 1.79%
- Veröffentlicht 11.12.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 02:01:30
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
CVE-2013-7370
- EPSS 1.08%
- Veröffentlicht 11.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 02:00:51
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-0163
- EPSS 0.12%
- Veröffentlicht 05.12.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 01:46:58
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
CVE-2013-2103
- EPSS 0.31%
- Veröffentlicht 03.12.2019 14:15:09
- Zuletzt bearbeitet 21.11.2024 01:51:02
OpenShift cartridge allows remote URL retrieval
CVE-2012-6135
- EPSS 1.27%
- Veröffentlicht 19.11.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 01:45:53
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
CVE-2014-0023
- EPSS 0.12%
- Veröffentlicht 15.11.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 02:01:11
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
CVE-2013-5123
- EPSS 12.86%
- Veröffentlicht 05.11.2019 22:15:10
- Zuletzt bearbeitet 21.11.2024 01:57:03
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
CVE-2013-0165
- EPSS 0.35%
- Veröffentlicht 01.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:46:58
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
CVE-2019-14845
- EPSS 0.04%
- Veröffentlicht 08.10.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:27:29
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and in...
CVE-2019-6648
- EPSS 0.11%
- Veröffentlicht 04.09.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:46:52
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by ...