VendorsRed Hatopenshift_container_platform_for_powerall versions
Vulnerabilities

Red Hat OpenShift Container Platform

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

23CVEs
CVE-2022-4361
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
Published 2023-07-07 · Modified
10.0EPSS 0.006
CVE-2022-4039
Rhsso-container-image: unsecured management interface exposed to adjecent network
Published 2023-09-22 · Modified
9.8EPSS 0.008
CVE-2024-1132
Keycloak: path transversal in redirection validation
Published 2024-04-17 · Analyzed
8.1EPSS 0.016
CVE-2023-2585
Keycloak: client access via device auth request spoof
Published 2023-12-21 · Modified
8.1EPSS 0.007
CVE-2019-0211
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
Published 2019-04-08 · Analyzed
7.8KEV1 PoCEPSS 0.650
CVE-2022-4318
Cri-o: /etc/passwd tampering privesc
Published 2023-09-25 · Modified
7.8EPSS 0.003
CVE-2023-6563
Keycloak: offline session token dos
Published 2023-12-14 · Modified
7.7EPSS 0.012
CVE-2025-13601
Glib: integer overflow in in g_escape_uri_string()
Published 2025-11-26 · Modified
7.7EPSS 0.003
CVE-2024-1635
Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol
Published 2024-02-19 · Modified
7.5EPSS 0.046
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2025-6021
Libxml2: integer overflow in xmlbuildqname() leads to stack buffer overflow in libxml2
Published 2025-06-12 · Modified
7.5EPSS 0.014
CVE-2026-4424
Libarchive: libarchive: information disclosure via heap out-of-bounds read in rar archive processing
Published 2026-03-19 · Modified
7.5EPSS 0.011
CVE-2023-5625
Python-eventlet: patch regression for cve-2021-21419 in some red hat builds
Published 2023-11-01 · Modified
7.5EPSS 0.008
CVE-2023-3089
Ocp & fips mode
Published 2023-07-05 · Modified
7.5EPSS 0.005
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2022-3916
Keycloak: session takeover with oidc offline refreshtokens
Published 2023-09-20 · Modified
6.8EPSS 0.010
CVE-2023-0056
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Published 2023-03-23 · Modified
6.5EPSS 0.018
CVE-2024-9676
Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)
Published 2024-10-15 · Modified
6.5EPSS 0.013
CVE-2024-4629
Keycloak: potential bypass of brute force protection
Published 2024-09-03 · Modified
6.5EPSS 0.008
CVE-2024-1725
Kubevirt-csi: persistentvolume allows access to hcp's root node
Published 2024-03-07 · Modified
6.5EPSS 0.006
CVE-2024-8883
Keycloak: vulnerable redirect uri validation results in open redirec
Published 2024-09-19 · Modified
6.1EPSS 0.021
CVE-2023-6134
Keycloak: reflected xss via wildcard in oidc redirect_uri
Published 2023-12-14 · Modified
5.4EPSS 0.013