VendorsRed Hatopenshiftany version
Vulnerabilities

Red Hat RedHat OpenShift any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2021-39013
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
Published 2021-12-22 · Modified
6.5EPSS 0.008
CVE-2022-2403
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-config-managed namespace, compromising any web traffic secured using that certificate.
Published 2022-09-01 · Modified
6.5EPSS 0.006
CVE-2022-43922
IBM App Connect Enterprise Certified Container information disclosure
Published 2023-02-01 · Modified
6.5EPSS 0.004
CVE-2019-4239
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
Published 2019-06-14 · Modified
6.2EPSS 0.003
CVE-2023-40694
IBM Watson CP4D Data Stores information disclosure
Published 2024-05-07 · Analyzed
6.2EPSS 0.002
CVE-2020-1761
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
Published 2021-05-27 · Modified
6.1EPSS 0.006
CVE-2014-3663
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
Published 2014-10-16 · Modified
6.0EPSS 0.014
CVE-2023-22863
IBM Robotic Process Automation information disclosure
Published 2023-01-18 · Modified
5.9EPSS 0.004
CVE-2019-14845
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
Published 2019-10-08 · Modified
5.7EPSS 0.004
CVE-2014-0068
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Published 2022-06-30 · Modified
5.5EPSS 0.002
CVE-2021-29906
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630.
Published 2021-10-08 · Modified
5.5EPSS 0.002
CVE-2023-23468
IBM Robotic Process Automation for Cloud Pak access control
Published 2023-06-27 · Modified
5.5EPSS 0.002
CVE-2021-29912
IBM Security Risk Manager on CP4S 1.7.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 207828.
Published 2021-10-19 · Modified
5.4EPSS 0.005
CVE-2023-22594
IBM Robotic Process Automation for Cloud Pak cross-site scripting
Published 2023-01-18 · Modified
5.4EPSS 0.004
CVE-2017-15137
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Published 2018-07-16 · Modified
5.3EPSS 0.010
CVE-2023-35900
IBM Robotic Process Automation information disclosure
Published 2023-07-19 · Modified
5.3EPSS 0.005
CVE-2023-40370
IBM Robotic Process Automation information disclosure
Published 2023-08-22 · Modified
5.3EPSS 0.005
CVE-2022-43573
IBM Robotic Process Automation information disclosure
Published 2023-01-05 · Modified
5.3EPSS 0.005
CVE-2023-35901
IBM Robotic Process Automation security bypass
Published 2023-07-16 · Modified
5.3EPSS 0.005
CVE-2015-5322
Directory traversal vulnerability in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to list directory contents and read arbitrary files in the Jenkins servlet resources via directory traversal sequences in a request to jnlpJars/.
Published 2015-11-25 · Modified
5.0EPSS 0.032
CVE-2015-5319
XML external entity (XXE) vulnerability in the create-job CLI command in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to read arbitrary files via a crafted job configuration that is then used in an "XML-aware tool," as demonstrated by get-job and update-job.
Published 2015-11-25 · Modified
5.0EPSS 0.023
CVE-2015-5320
Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to connect as slaves and obtain sensitive information or possibly gain administrative access by leveraging knowledge of the name of a slave.
Published 2015-11-25 · Modified
5.0EPSS 0.021
CVE-2015-5321
The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to the pages.
Published 2015-11-25 · Modified
5.0EPSS 0.021
CVE-2015-5324
Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.
Published 2015-11-25 · Modified
5.0EPSS 0.021
CVE-2014-3661
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
Published 2014-10-16 · Modified
5.0EPSS 0.018
CVE-2014-3662
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
Published 2014-10-16 · Modified
5.0EPSS 0.017
CVE-2021-38911
IBM Security Risk Manager on CP4S 1.7.0.0 stores user credentials in plain clear text which can be read by a an authenticatedl privileged user. IBM X-Force ID: 209940.
Published 2021-10-19 · Modified
4.9EPSS 0.005
CVE-2015-1810
The HudsonPrivateSecurityRealm class in Jenkins before 1.600 and LTS before 1.596.1 does not restrict access to reserved names when using the "Jenkins' own user database" setting, which allows remote attackers to gain privileges by creating a reserved name.
Published 2015-10-16 · Modified
4.6EPSS 0.016
CVE-2021-3636
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates signed by the trusted Service CA. The incorrect inclusion of additional CAs in this certificate would allow an attacker that compromises any of the additional CAs to masquerade as a trusted in-cluster service.
Published 2021-07-30 · Modified
4.6EPSS 0.003
CVE-2022-41740
IBM Robotic Process Automation information disclosure
Published 2023-01-05 · Modified
4.6EPSS 0.002
CVE-2019-6648
On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BIG-IP secrets such as SSL Private Keys and Private key Passphrases as provided as inputs by an AS3 Declaration.
Published 2019-09-04 · Modified
4.4EPSS 0.003
CVE-2025-36187
Multiple Security vulnerabilities affecting IBM Knowledge Catalog Standard Cartridge
Published 2026-03-25 · Analyzed
4.4EPSS 0.002
CVE-2014-1869
Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
Published 2014-02-08 · Modified
4.3EPSS 0.028
CVE-2014-3681
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2014-10-15 · Modified
4.3EPSS 0.021
CVE-2015-5326
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
Published 2015-11-25 · Modified
4.3EPSS 0.018
CVE-2015-1812
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.
Published 2015-10-16 · Modified
4.3EPSS 0.018
CVE-2015-1813
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.
Published 2015-10-16 · Modified
4.3EPSS 0.018
CVE-2020-10715
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x. This flaw allows an attacker to craft a URL and inject arbitrary text onto the error page that appears to be from the OpenShift instance. This attack could potentially convince a user that the inserted text is legitimate.
Published 2020-09-16 · Modified
4.3EPSS 0.009
CVE-2023-38732
IBM Robotic Process Automation information disclosure
Published 2023-08-22 · Modified
4.3EPSS 0.005
CVE-2023-38733
IBM Robotic Process Automation information disclosure
Published 2023-08-22 · Modified
4.3EPSS 0.005
← Prev2 / 3Next →