Red Hat / Openshift
148 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-35092 | Corosync: corosync: denial of service via integer overflow in join message validation | HIGH | 7.5 | Apr 1, 2026 |
| CVE-2026-35091 | Corosync: corosync: denial of service and information disclosure via crafted udp packet | HIGH | 8.2 | Apr 1, 2026 |
| CVE-2025-14512 | Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow | MEDIUM | 6.5 | Dec 11, 2025 |
| CVE-2024-45777 | Grub2: grub-core/gettext: integer overflow leads to heap oob write. | MEDIUM | 6.7 | Feb 19, 2025 |
| CVE-2024-12085 | Rsync: info leak via uninitialized stack contents | HIGH | 7.5 | Jan 14, 2025 |
| CVE-2024-1485 | Registry-support: decompress can delete files outside scope via relative paths | MEDIUM | 4.6 | Feb 13, 2024 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-0229 | openshift/apiserver-library-go: Bypass of SCC seccomp profile restrictions | MEDIUM | 6.3 | Jan 25, 2023 |
| CVE-2023-0296 | openshift: etcd grpc-proxy vulnerable to The Birthday attack against 64-bit block cipher | MEDIUM | 5.3 | Jan 17, 2023 |
| CVE-2022-3259 | OpenShift: Missing HTTP Strict Transport Security | HIGH | 7.4 | Dec 9, 2022 |
| CVE-2022-3262 | openshift: insecure default DNSPolicy for pods | HIGH | 8.1 | Dec 8, 2022 |
| CVE-2022-3260 | Openshift: Missing X-Frame-Options Header | MEDIUM | 6.5 | Dec 8, 2022 |
| CVE-2013-4281 | In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with loca… | MEDIUM | 5.5 | Oct 19, 2022 |
| CVE-2013-4253 | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's aut… | HIGH | 7.5 | Oct 19, 2022 |
| CVE-2017-7517 | 3: Metrics accessible from reused project name | LOW | 3.5 | Oct 17, 2022 |
| CVE-2022-2403 | openshift: oauth-serving-cert configmap contains cluster certificate private key | HIGH | 7.7 | Sep 1, 2022 |
| CVE-2021-4125 | kube-reporting/hive: Incomplete fix for log4j CVE-2021-44228 and CVE-2021-45046 | HIGH | 8.1 | Aug 24, 2022 |
| CVE-2021-3697 | grub2: Crafted JPEG image can lead to buffer underflow write in the heap | HIGH | 7.5 | Jul 6, 2022 |
| CVE-2021-3696 | grub2: Crafted PNG image may lead to out-of-bound write during huffman table handling | MEDIUM | 5.0 | Jul 6, 2022 |
| CVE-2021-3695 | grub2: Crafted PNG grayscale images may lead to out-of-bounds write in heap | HIGH | 7.5 | Jul 6, 2022 |
| CVE-2013-4561 | openshift-origin-msg-node-mcollective: /etc/cron.minutely/openshift-facts tmp file creation | CRITICAL | 9.1 | Jun 30, 2022 |
| CVE-2021-4047 | haproxy: Incomplete fix for CVE-2021-39242 in OpenShift 4.9 | HIGH | 7.5 | Apr 11, 2022 |
| CVE-2021-3636 | openshift: Injected service-ca.crt incorrectly contains additional internal CAs | MEDIUM | 4.6 | Jul 30, 2021 |
| CVE-2020-35514 | openshift/machine-config-operator: /etc/kubernetes/kubeconfig is given incorrect privileges | HIGH | 7.0 | Jun 2, 2021 |
| CVE-2020-1761 | openshift/console: access token stored in browser local storage | MEDIUM | 6.3 | May 27, 2021 |
Showing 1 to 25 of 148 CVEs