VendorsRed Hatopenshift_container_platform4.12
Vulnerabilities

Red Hat OpenShift Container Platform 4.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2022-4361
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
Published 2023-07-07 · Modified
10.0EPSS 0.006
CVE-2024-9341
Podman: buildah: cri-o: fips crypto-policy directory mounting issue in containers/common go library
Published 2024-10-01 · Modified
8.2EPSS 0.010
CVE-2024-1132
Keycloak: path transversal in redirection validation
Published 2024-04-17 · Analyzed
8.1EPSS 0.016
CVE-2023-4853
Quarkus: http security policy bypass
Published 2023-09-20 · Modified
8.1EPSS 0.014
CVE-2024-5154
Cri-o: malicious container can create symlink on host
Published 2024-06-12 · Modified
8.1EPSS 0.012
CVE-2023-2585
Keycloak: client access via device auth request spoof
Published 2023-12-21 · Modified
8.1EPSS 0.007
CVE-2023-1260
Kube-apiserver: privesc
Published 2023-09-24 · Modified
8.0EPSS 0.016
CVE-2023-6563
Keycloak: offline session token dos
Published 2023-12-14 · Modified
7.7EPSS 0.012
CVE-2025-13601
Glib: integer overflow in in g_escape_uri_string()
Published 2025-11-26 · Modified
7.7EPSS 0.003
CVE-2024-12085
Rsync: info leak via uninitialized stack contents
Published 2025-01-14 · Modified
7.5EPSS 0.088
CVE-2024-1635
Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol
Published 2024-02-19 · Modified
7.5EPSS 0.046
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2023-5408
Openshift: modification of node role labels
Published 2023-11-02 · Modified
7.2EPSS 0.011
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2023-2422
Keycloak: oauth client impersonation
Published 2023-10-04 · Modified
7.1EPSS 0.005
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Published 2023-03-23 · Modified
6.5EPSS 0.018
CVE-2024-9676
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Published 2024-10-15 · Modified
6.5EPSS 0.013
CVE-2024-4629
Keycloak: potential bypass of brute force protection
Published 2024-09-03 · Modified
6.5EPSS 0.008
CVE-2024-8883
Keycloak: vulnerable redirect uri validation results in open redirec
Published 2024-09-19 · Modified
6.1EPSS 0.021
CVE-2023-4065
Operator: plaintext password in operator log
Published 2023-09-26 · Modified
5.5EPSS 0.002
CVE-2023-4066
Operator: passwords defined in secrets shown in statefulset yaml
Published 2023-09-27 · Modified
5.5EPSS 0.002
CVE-2023-6134
Keycloak: reflected xss via wildcard in oidc redirect_uri
Published 2023-12-14 · Modified
5.4EPSS 0.013
CVE-2022-3466
Cri-o: security regression of cve-2022-27652
Published 2023-09-15 · Modified
5.3EPSS 0.002