VendorsRed Hatopenshiftall versions
Vulnerabilities

Red Hat RedHat OpenShift

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

181CVEs
CVE-2026-22549
BIG-IP Container Ingress Services vulnerability
Published 2026-02-04 · Analyzed
6.9EPSS 0.003
CVE-2016-5392
The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowledge of other project names to obtain sensitive project and user information via vectors related to the watch-cache list.
Published 2016-08-05 · Modified
6.8EPSS 0.025
CVE-2020-1759
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
Published 2020-04-13 · Modified
6.8EPSS 0.016
CVE-2015-5318
Jenkins before 1.638 and LTS before 1.625.2 uses a publicly accessible salt to generate CSRF protection tokens, which makes it easier for remote attackers to bypass the CSRF protection mechanism via a brute force attack.
Published 2015-11-25 · Modified
6.8EPSS 0.012
CVE-2022-42439
IBM App Connect Enterprise information disclosure
Published 2023-02-06 · Modified
6.8EPSS 0.007
CVE-2012-5622
Cross-site request forgery (CSRF) vulnerability in the management console (openshift-console/app/controllers/application_controller.rb) in OpenShift 0.0.5 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors.
Published 2012-12-18 · Modified
6.8EPSS 0.007
CVE-2024-45777
Grub2: grub-core/gettext: integer overflow leads to heap oob write.
Published 2025-02-19 · Modified
6.7EPSS 0.002
CVE-2018-1257
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.
Published 2018-05-11 · Modified
6.5EPSS 0.031
CVE-2015-1806
The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permission to gain privileges and execute arbitrary code on the master via unspecified vectors.
Published 2015-10-16 · Modified
6.5EPSS 0.025
CVE-2016-3724
Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by reading a job configuration.
Published 2016-05-17 · Modified
6.5EPSS 0.022
CVE-2016-3721
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
Published 2016-05-17 · Modified
6.5EPSS 0.021
CVE-2015-5274
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
Published 2015-09-18 · Modified
6.5EPSS 0.021
CVE-2014-0233
Red Hat OpenShift Enterprise 2.0 and 2.1 and OpenShift Origin allow remote authenticated users to execute arbitrary commands via shell metacharacters in a directory name that is referenced by a cartridge using the file: URI scheme.
Published 2014-11-16 · Modified
6.5EPSS 0.017
CVE-2016-2149
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace.
Published 2016-06-08 · Modified
6.5EPSS 0.015
CVE-2015-5323
Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges and run scripts by using an API token of another user.
Published 2015-11-25 · Modified
6.5EPSS 0.015
CVE-2021-39013
IBM Cloud Pak for Security (CP4S) 1.7.2.0, 1.7.1.0, and 1.7.0.0 could allow an authenticated user to obtain sensitive information in HTTP responses that could be used in further attacks against the system. IBM X-Force ID: 213651.
Published 2021-12-22 · Modified
6.5EPSS 0.008
CVE-2019-10225
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.
Published 2021-03-19 · Modified
6.5EPSS 0.006
CVE-2025-14512
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Published 2025-12-11 · Modified
6.5EPSS 0.006
CVE-2022-2403
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-config-managed namespace, compromising any web traffic secured using that certificate.
Published 2022-09-01 · Modified
6.5EPSS 0.006
CVE-2013-0196
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
Published 2019-12-30 · Modified
6.5EPSS 0.004
CVE-2022-43922
IBM App Connect Enterprise Certified Container information disclosure
Published 2023-02-01 · Modified
6.5EPSS 0.004
CVE-2015-5305
Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly handled before passing it to etcd.
Published 2015-11-06 · Modified
6.4EPSS 0.018
CVE-2023-0229
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.
Published 2023-01-25 · Modified
6.3EPSS 0.006
CVE-2019-4239
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
Published 2019-06-14 · Modified
6.2EPSS 0.003
CVE-2023-40694
IBM Watson CP4D Data Stores information disclosure
Published 2024-05-07 · Analyzed
6.2EPSS 0.002
CVE-2016-1000229
swagger-ui has XSS in key names
Published 2019-12-20 · Modified
6.1EPSS 0.040
CVE-2016-0789
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Published 2016-04-07 · Modified
6.1EPSS 0.018
CVE-2013-7370
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
Published 2019-12-11 · Modified
6.1EPSS 0.014
CVE-2018-1059
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
Published 2018-04-24 · Modified
6.1EPSS 0.009
CVE-2020-1761
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw affects openshift/console versions before openshift/console-4.
Published 2021-05-27 · Modified
6.1EPSS 0.006
CVE-2014-3663
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
Published 2014-10-16 · Modified
6.0EPSS 0.014
CVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.
Published 2019-11-05 · Modified
5.91 PoCEPSS 0.080
CVE-2023-22863
IBM Robotic Process Automation information disclosure
Published 2023-01-18 · Modified
5.9EPSS 0.004
CVE-2012-2125
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
Published 2013-10-01 · Modified
5.8EPSS 0.025
CVE-2012-5647
Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO.
Published 2013-02-24 · Modified
5.8EPSS 0.015
CVE-2019-14845
A vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hostname verification. An attacker can take advantage of this flaw by launching a man-in-the-middle attack and injecting malicious content.
Published 2019-10-08 · Modified
5.7EPSS 0.004
CVE-2016-2142
Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local users to obtain Active Directory credentials by reading the file.
Published 2016-06-08 · Modified
5.5EPSS 0.004
CVE-2013-0163
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
Published 2019-12-05 · Modified
5.5EPSS 0.003
CVE-2014-0068
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
Published 2022-06-30 · Modified
5.5EPSS 0.002
CVE-2021-29906
IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a local user when it is configured to use an IBM Cloud API key to connect to cloud-based connectors. IBM X-Force ID: 207630.
Published 2021-10-08 · Modified
5.5EPSS 0.002
← Prev3 / 5Next →