VendorsRed Hatopenshiftall versions
Vulnerabilities

Red Hat RedHat OpenShift

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

181CVEs
CVE-2015-7501
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Published 2017-11-09 · Modified
10.0EPSS 0.856
CVE-2016-0788
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
Published 2016-04-07 · Modified
10.0EPSS 0.118
CVE-2013-2060
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
Published 2020-01-28 · Modified
10.0EPSS 0.055
CVE-2014-3496
cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file.
Published 2014-06-20 · Modified
10.0EPSS 0.051
CVE-2015-5254
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.
Published 2016-01-08 · Modified
9.8EPSS 0.382
CVE-2016-2074
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.
Published 2016-07-03 · Modified
9.8EPSS 0.063
CVE-2014-0234
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.
Published 2020-02-12 · Modified
9.8EPSS 0.038
CVE-2016-0791
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.
Published 2016-04-07 · Modified
9.8EPSS 0.027
CVE-2014-0175
mcollective has a default password set at install
Published 2019-12-13 · Modified
9.8EPSS 0.020
CVE-2021-20578
IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized actions due to improper or missing authentication controls. IBM X-Force ID: 199282.
Published 2021-09-30 · Modified
9.8EPSS 0.010
CVE-2022-41731
IBM Watson Knowledge Catalog on Cloud Pak SQL injection
Published 2023-02-06 · Modified
9.8EPSS 0.009
CVE-2023-38734
IBM Robotic Process Automation privilege escalation
Published 2023-08-22 · Modified
9.8EPSS 0.007
CVE-2023-43058
IBM Robotic Process Automation privilege escalation
Published 2023-10-06 · Modified
9.8EPSS 0.006
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.
Published 2019-02-11 · Modified
9.32 PoCEPSS 0.985
CVE-2024-1485
Registry-support: decompress can delete files outside scope via relative paths
Published 2024-02-13 · Modified
9.3EPSS 0.009
CVE-2013-4561
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.
Published 2022-06-30 · Modified
9.1EPSS 0.014
CVE-2022-43916
IBM App Connect Enterprise Certified Container improper communications restriction
Published 2025-01-30 · Analyzed
9.1EPSS 0.003
CVE-2016-0792
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.
Published 2016-04-07 · Modified
9.02 PoCEPSS 0.833
CVE-2016-2160
Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image.
Published 2016-06-08 · Modified
9.0EPSS 0.041
CVE-2014-0163
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
Published 2019-12-11 · Modified
9.0EPSS 0.020
CVE-2016-5766
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.
Published 2016-08-07 · Modified
8.8EPSS 0.075
CVE-2018-1102
A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.
Published 2018-04-30 · Modified
8.8EPSS 0.024
CVE-2015-7537
Cross-site request forgery (CSRF) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote attackers to hijack the authentication of administrators for requests that have unspecified impact via vectors related to the HTTP GET method.
Published 2016-02-03 · Modified
8.8EPSS 0.024
CVE-2015-7538
Jenkins before 1.640 and LTS before 1.625.2 allow remote attackers to bypass the CSRF protection mechanism via unspecified vectors.
Published 2016-02-03 · Modified
8.8EPSS 0.022
CVE-2016-3738
Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.
Published 2016-06-08 · Modified
8.8EPSS 0.019
CVE-2022-43844
IBM Robotic Process Automation for Cloud Pak session fixation
Published 2023-01-05 · Modified
8.8EPSS 0.007
CVE-2024-51465
IBM App Connect Enterprise Certified Container command execution
Published 2024-12-04 · Analyzed
8.8EPSS 0.007
CVE-2015-5222
Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.
Published 2015-08-24 · Modified
8.5EPSS 0.027
CVE-2026-35091
Corosync: corosync: denial of service and information disclosure via crafted udp packet
Published 2026-04-01 · Modified
8.2EPSS 0.009
CVE-2016-7075
It was found that Kubernetes as used by Openshift Enterprise 3 did not correctly validate X.509 client intermediate certificate host name fields. An attacker could use this flaw to bypass authentication requirements by using a specially crafted X.509 certificate.
Published 2018-09-10 · Modified
8.1EPSS 0.016
CVE-2021-4125
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.
Published 2022-08-24 · Modified
8.1EPSS 0.015
CVE-2013-2103
OpenShift cartridge allows remote URL retrieval
Published 2019-12-03 · Modified
8.1EPSS 0.010
CVE-2022-3262
A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.
Published 2022-12-08 · Modified
8.1EPSS 0.007
CVE-2018-10875
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
Published 2018-07-13 · Modified
7.8EPSS 0.006
CVE-2013-4364
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
Published 2018-01-08 · Modified
7.8EPSS 0.004
CVE-2014-0023
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
Published 2019-11-15 · Modified
7.8EPSS 0.004
CVE-2019-19350
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2021-03-24 · Modified
7.8EPSS 0.003
CVE-2019-19349
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2021-03-24 · Modified
7.8EPSS 0.003
CVE-2020-1709
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2020-03-20 · Modified
7.8EPSS 0.003
CVE-2019-19345
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2020-03-20 · Modified
7.8EPSS 0.003
1 / 5Next →