VendorsRed Hatopenshiftany version
Vulnerabilities

Red Hat RedHat OpenShift any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

88CVEs
CVE-2014-3664
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
Published 2014-10-15 · Modified
4.0EPSS 0.025
CVE-2014-3667
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
Published 2014-10-16 · Modified
4.0EPSS 0.014
CVE-2014-3680
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
Published 2014-10-16 · Modified
4.0EPSS 0.014
CVE-2013-0164
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
Published 2013-02-24 · Modified
3.6EPSS 0.004
CVE-2015-1807
Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.
Published 2015-10-16 · Modified
3.5EPSS 0.018
CVE-2015-1808
Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.
Published 2015-10-16 · Modified
3.5EPSS 0.016
CVE-2014-3602
Red Hat OpenShift Enterprise before 2.2 allows local users to obtain IP address and port number information for remote systems by reading /proc/net/tcp.
Published 2014-11-13 · Modified
2.1EPSS 0.004
CVE-2012-5658
rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels.
Published 2013-02-24 · Modified
2.1EPSS 0.004
← Prev3 / 3