VendorsRed Hatopenshift_container_platform3.9
Vulnerabilities

Red Hat OpenShift Container Platform 3.9

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2018-10843
source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.
Published 2018-07-02 · Modified
9.0EPSS 0.014
CVE-2019-11247
Kubernetes kube-apiserver allows access to custom resources via wrong scope
Published 2019-08-29 · Modified
8.1EPSS 0.021
CVE-2019-9514
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service
Published 2019-08-13 · Modified
7.8EPSS 0.828
CVE-2018-14632
An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.
Published 2018-09-06 · Modified
7.7EPSS 0.020
CVE-2019-11253
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Published 2019-10-17 · Analyzed
7.5EPSS 0.259
CVE-2018-14645
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Published 2018-09-21 · Modified
7.5EPSS 0.030
CVE-2019-11249
kubectl cp allows symlink directory traversal
Published 2019-08-29 · Modified
6.5EPSS 0.037
CVE-2019-1002101
kubectl cp path traversal
Published 2019-04-01 · Modified
6.4EPSS 0.127
CVE-2017-15137
The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be allowed.
Published 2018-07-16 · Modified
5.3EPSS 0.010
CVE-2017-15138
The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook tokens.
Published 2018-08-13 · Modified
5.0EPSS 0.009