VendorsRed Hatopenshift_container_platform3.10
Vulnerabilities

Red Hat OpenShift Container Platform 3.10

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.
Published 2018-12-05 · Modified
9.82 PoCEPSS 0.870
CVE-2018-14718
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
Published 2019-01-02 · Modified
9.8EPSS 0.127
CVE-2019-14819
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged Security Context Constraints.
Published 2020-01-07 · Modified
8.8EPSS 0.011
CVE-2019-11247
Kubernetes kube-apiserver allows access to custom resources via wrong scope
Published 2019-08-29 · Modified
8.1EPSS 0.021
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2018-14632
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
Published 2018-09-06 · Modified
7.7EPSS 0.020
CVE-2019-11253
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Published 2019-10-17 · Analyzed
7.5EPSS 0.259
CVE-2019-1002100
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Published 2019-04-01 · Modified
6.5EPSS 0.108
CVE-2019-11249
kubectl cp allows symlink directory traversal
Published 2019-08-29 · Modified
6.5EPSS 0.037
CVE-2019-1002101
kubectl cp path traversal
Published 2019-04-01 · Modified
6.4EPSS 0.127