VendorsRed Hatopenshift4.0
Vulnerabilities

Red Hat RedHat OpenShift 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-1485
Registry-support: decompress can delete files outside scope via relative paths
Published 2024-02-13 · Modified
9.3EPSS 0.009
CVE-2026-35091
Corosync: corosync: denial of service and information disclosure via crafted udp packet
Published 2026-04-01 · Modified
8.2EPSS 0.011
CVE-2019-19350
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2021-03-24 · Modified
7.8EPSS 0.003
CVE-2019-19349
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
Published 2021-03-24 · Modified
7.8EPSS 0.003
CVE-2026-35092
Corosync: corosync: denial of service via integer overflow in join message validation
Published 2026-04-01 · Modified
7.5EPSS 0.013
CVE-2019-19351
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in Openshift 4 and 3.11.
Published 2020-03-18 · Modified
7.0EPSS 0.003
CVE-2019-19355
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift 4.
Published 2020-03-18 · Modified
7.0EPSS 0.002
CVE-2024-45777
Grub2: grub-core/gettext: integer overflow leads to heap oob write.
Published 2025-02-19 · Modified
6.7EPSS 0.002
CVE-2025-14512
Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
Published 2025-12-11 · Modified
6.5EPSS 0.006
CVE-2019-19335
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer as shipped in Openshift 4.2 is vulnerable.
Published 2020-03-18 · Modified
4.4EPSS 0.003