VendorsRed Hatopenshift_container_platformall versions
Vulnerabilities

Red Hat OpenShift Container Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

326CVEs
CVE-2019-11249
kubectl cp allows symlink directory traversal
Published 2019-08-29 · Modified
6.5EPSS 0.037
CVE-2018-13988
Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file.
Published 2018-07-25 · Modified
6.5EPSS 0.032
CVE-2018-1000864
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread enter an infinite loop.
Published 2018-12-10 · Modified
6.5EPSS 0.028
CVE-2019-11255
Kubernetes CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation
Published 2019-12-05 · Modified
6.5EPSS 0.020
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Published 2023-03-23 · Modified
6.5EPSS 0.018
CVE-2019-10223
A security issue was discovered in the kube-state-metrics versions v1.7.0 and v1.7.1. An experimental feature was added to the v1.7.0 release that enabled annotations to be exposed as metrics. By default, the kube-state-metrics metrics only expose metadata about Secrets. However, a combination of the default `kubectl` behavior and this new feature can cause the entire secret content to end up in metric labels thus inadvertently exposing the secret content in metrics. This feature has been reverted and released as the v1.7.2 release. If you are running the v1.7.0 or v1.7.1 release, please upgrade to the v1.7.2 release as soon as possible.
Published 2019-11-05 · Modified
6.5EPSS 0.018
CVE-2019-11250
Kubernetes client-go logs authorization headers at debug verbosity levels
Published 2019-08-29 · Modified
6.5EPSS 0.018
CVE-2017-12195
A flaw was found in all Openshift Enterprise versions using the openshift elasticsearch plugin. An attacker with knowledge of the given name used to authenticate and access Elasticsearch can later access it without the token, bypassing authentication. This attack also requires that the Elasticsearch be configured with an external route, and the data accessed is limited to the indices.
Published 2018-07-27 · Modified
6.5EPSS 0.014
CVE-2024-9676
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Published 2024-10-15 · Modified
6.5EPSS 0.013
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Published 2022-05-17 · Modified
6.5EPSS 0.013
CVE-2019-1003012
A data modification vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-core-js/src/js/bundleStartup.js, blueocean-core-js/src/js/fetch.ts, blueocean-core-js/src/js/i18n/i18n.js, blueocean-core-js/src/js/urlconfig.js, blueocean-rest/src/main/java/io/jenkins/blueocean/rest/APICrumbExclusion.java, blueocean-web/src/main/java/io/jenkins/blueocean/BlueOceanUI.java, blueocean-web/src/main/resources/io/jenkins/blueocean/BlueOceanUI/index.jelly that allows attackers to bypass all cross-site request forgery protection in Blue Ocean API.
Published 2019-02-06 · Modified
6.5EPSS 0.011
CVE-2019-10213
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Published 2019-11-25 · Modified
6.5EPSS 0.010
CVE-2026-2340
Samba: vfs_worm does not block directory modification
Published 2026-05-27 · Modified
6.5EPSS 0.009
CVE-2023-2253
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array, possibly causing a denial of service through excessive use of memory.
Published 2023-06-06 · Modified
6.5EPSS 0.009
CVE-2020-14336
A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Platform cluster if they can deploy pods. The highest threat from this vulnerability is to system availability.
Published 2021-06-02 · Modified
6.5EPSS 0.009
CVE-2019-14854
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
Published 2020-01-07 · Modified
6.5EPSS 0.008
CVE-2024-4629
Keycloak: potential bypass of brute force protection
Published 2024-09-03 · Modified
6.5EPSS 0.008
CVE-2024-1725
Kubevirt-csi: persistentvolume allows access to hcp's root node
Published 2024-03-07 · Modified
6.5EPSS 0.006
CVE-2024-50311
Graphql: denial of service (dos) vulnerability via graphql batching
Published 2024-10-22 · Modified
6.5EPSS 0.006
CVE-2019-10225
A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate to the GlusterFS REST service, gaining access to read, and modify files.
Published 2021-03-19 · Modified
6.5EPSS 0.006
CVE-2026-9150
Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2025-5351
Libssh: double free vulnerability in libssh key export functions
Published 2025-07-04 · Modified
6.5EPSS 0.006
CVE-2026-9149
Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
Published 2026-05-20 · Modified
6.5EPSS 0.006
CVE-2026-4426
Libarchive: libarchive: denial of service via malformed iso file processing
Published 2026-03-19 · Modified
6.5EPSS 0.006
CVE-2026-71225
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Published 2026-08-05 · Modified
6.5EPSS 0.005
CVE-2026-55653
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
Published 2026-06-23 · Modified
6.5EPSS 0.005
CVE-2025-12801
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
Published 2026-03-04 · Modified
6.5EPSS 0.005
CVE-2022-1632
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
Published 2022-09-01 · Modified
6.5EPSS 0.004
CVE-2024-7079
Openshift-console: unauthenticated installation of helm charts
Published 2024-07-24 · Modified
6.5EPSS 0.004
CVE-2022-0669
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts available fd in the vhost-user slave process, leading to a denial of service.
Published 2022-08-29 · Modified
6.5EPSS 0.003
CVE-2019-1002101
kubectl cp path traversal
Published 2019-04-01 · Modified
6.4EPSS 0.127
CVE-2019-10214
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Published 2019-11-25 · Modified
6.4EPSS 0.016
CVE-2020-15707
GRUB2 contained integer overflows when handling the initrd command, leading to a heap-based buffer overflow.
Published 2020-07-29 · Modified
6.4EPSS 0.016
CVE-2020-15705
GRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shim
Published 2020-07-29 · Modified
6.4EPSS 0.014
CVE-2020-15706
GRUB2 contains a race condition leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing.
Published 2020-07-29 · Modified
6.4EPSS 0.010
CVE-2019-3876
A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens.
Published 2019-04-01 · Modified
6.3EPSS 0.007
CVE-2022-1677
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
Published 2022-09-01 · Modified
6.3EPSS 0.006
CVE-2021-3631
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt confinement. The highest threat from this vulnerability is to confidentiality and integrity.
Published 2022-03-02 · Modified
6.3EPSS 0.005
CVE-2026-0964
Libssh: improper sanitation of paths received from scp servers
Published 2026-03-26 · Modified
6.3EPSS 0.004
CVE-2026-13757
P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing
Published 2026-06-29 · Modified
6.2EPSS 0.002
← Prev6 / 9Next →