VendorsRed Hatopenshift_container_platform4.0
Vulnerabilities

Red Hat OpenShift Container Platform 4.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

128CVEs
CVE-2022-1632
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
Published 2022-09-01 · Modified
6.5EPSS 0.004
CVE-2024-7079
Openshift-console: unauthenticated installation of helm charts
Published 2024-07-24 · Modified
6.5EPSS 0.004
CVE-2022-0669
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Published 2022-08-29 · Modified
6.5EPSS 0.003
CVE-2020-15707
GRUB2 contained integer overflows when handling the initrd command, leading to a heap-based buffer overflow.
Published 2020-07-29 · Modified
6.4EPSS 0.016
CVE-2020-15705
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
Published 2020-07-29 · Modified
6.4EPSS 0.014
CVE-2020-15706
GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.
Published 2020-07-29 · Modified
6.4EPSS 0.010
CVE-2026-0964
Libssh: improper sanitation of paths received from scp servers
Published 2026-03-26 · Modified
6.3EPSS 0.004
CVE-2020-27816
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL redirection or the openshift-logging console link damage. This flaw affects elasticsearch-operator-container versions before 4.7.
Published 2020-12-02 · Modified
6.1EPSS 0.007
CVE-2026-4647
Binutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
Published 2026-03-23 · Modified
6.1EPSS 0.002
CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
Published 2020-06-03 · Modified
6.0EPSS 0.024
CVE-2023-48795
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
Published 2023-12-18 · Modified
5.9EPSS 0.933
CVE-2026-0990
Libxml2: libxml2: denial of service via uncontrolled recursion in xml catalog processing
Published 2026-01-15 · Analyzed
5.9EPSS 0.010
CVE-2021-4294
OpenShift OSIN CheckClientSecret timing discrepancy
Published 2022-12-28 · Modified
5.9EPSS 0.007
CVE-2025-5916
Libarchive: integer overflow while reading warc files at archive_read_support_format_warc.c
Published 2025-06-09 · Modified
5.6EPSS 0.002
CVE-2020-10763
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
Published 2020-11-24 · Modified
5.5EPSS 0.004
CVE-2024-45778
Grub2: fs/bfs: integer overflow in the bfs parser.
Published 2025-03-03 · Modified
5.5EPSS 0.003
CVE-2021-20297
A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes NetworkManager. The highest threat from this vulnerability is to system availability.
Published 2021-05-26 · Modified
5.5EPSS 0.003
CVE-2026-5745
Libarchive: a null pointer dereference vulnerability exists in the acl parser of libarchive
Published 2026-04-07 · Modified
5.5EPSS 0.002
CVE-2026-19548
Binutils: binutils: multiple use-after-free in add_archive_element via lto plugin processing
Published 2026-08-12 · Analyzed
5.5EPSS 0.002
CVE-2026-4897
Polkit: polkit: denial of service via unbounded input processing through standard input
Published 2026-03-26 · Modified
5.5EPSS 0.002
CVE-2026-6245
Sssd: out-of-bounds read in the sssd
Published 2026-04-15 · Analyzed
5.5EPSS 0.001
CVE-2026-6844
Binutils: binutils: denial of service vulnerabilities in readelf via crafted elf files
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-6843
Nano: nano: format string vulnerability leads to denial of service
Published 2026-04-22 · Analyzed
5.5EPSS 0.001
CVE-2026-19617
Libdm: lvm2: libdm: denial of service via uncontrolled recursion in config parser
Published 2026-08-14 · Analyzed
5.5EPSS 0.001
CVE-2026-68742
Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr
Published 2026-08-03 · Analyzed
5.5EPSS 0.001
CVE-2025-32989
Gnutls: vulnerability in gnutls sct extension parsing
Published 2025-07-10 · Modified
5.3EPSS 0.013
CVE-2023-3153
Service monitor mac flow is not rate limited
Published 2023-10-04 · Modified
5.3EPSS 0.010
CVE-2022-4145
Content spoofing
Published 2023-10-05 · Modified
5.3EPSS 0.006
CVE-2024-50312
Graphql: information disclosure via graphql introspection in openshift
Published 2024-10-22 · Modified
5.3EPSS 0.006
CVE-2022-27652
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-18 · Modified
5.3EPSS 0.002
CVE-2026-71227
Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
Published 2026-08-05 · Modified
5.1EPSS 0.002
CVE-2026-10533
Openshift: openshift: non-admin user can bypass resourcequota and flood etcd with events causing cluster-wide api degradation
Published 2026-06-01 · Analyzed
5.0EPSS 0.002
CVE-2025-5917
Libarchive: off by one error in build_ustar_entry_name() at archive_write_set_format_pax.c
Published 2025-06-09 · Modified
5.0EPSS 0.002
CVE-2026-6845
Binutils: binutils: denial of service via crafted elf file
Published 2026-04-22 · Modified
5.0EPSS 0.001
CVE-2022-0718
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Published 2022-08-29 · Modified
4.9EPSS 0.017
CVE-2022-0532
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod with a hostIPC and hostNetwork kernel namespace.
Published 2022-02-09 · Modified
4.9EPSS 0.008
CVE-2025-4598
Systemd-coredump: race condition that allows a local attacker to crash a suid program and gain read access to the resulting core dump
Published 2025-05-30 · Modified
4.7EPSS 0.008
CVE-2026-13002
Dnsmasq: infinite loop dos in dnssec nsec/nsec3 type bitmap parsing
Published 2026-08-14 · Analyzed
4.4EPSS 0.001
CVE-2026-18508
Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
Published 2026-08-03 · Modified
4.4EPSS 0.001
CVE-2026-18477
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Published 2026-08-03 · Modified
4.4EPSS 0.001
← Prev3 / 4Next →