Red Hat / Openshift
148 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2014-0023 | OpenShift: install script has temporary file creation vulnerability | HIGH | 7.8 | Nov 15, 2019 |
| CVE-2013-5123 | python-pip: insecure software download with mirroring support | HIGH | 8.2 | Nov 5, 2019 |
| CVE-2013-0165 | cartridge: info/bin/dump.sh /tmp file creation | HIGH | 7.3 | Nov 1, 2019 |
| CVE-2019-14845 | openshift: Container image TLS verification bypass | MEDIUM | 5.3 | Oct 8, 2019 |
| CVE-2019-6648 | On version 1.9.0, If DEBUG logging is enable, F5 Container Ingress Service (CIS) for Kubernetes and Red Hat OpenShift (k8s-bigip-ctlr) log files may contain BI… | MEDIUM | 4.4 | Sep 4, 2019 |
| CVE-2019-3884 | atomic-openshift: cross-namespace owner references can trigger deletions of valid children | MEDIUM | 5.4 | Aug 1, 2019 |
| CVE-2019-10165 | openshift: OAuth access tokens written in plaintext to API server audit logs | LOW | 2.3 | Jul 30, 2019 |
| CVE-2019-5736 | runc: Execution of malicious containers allows for container escape and access to host filesystem | HIGH | 8.6 | Feb 11, 2019 |
| CVE-2018-14645 | haproxy: Out-of-bounds read in HPACK decoder | HIGH | 7.5 | Sep 21, 2018 |
| CVE-2016-7075 | 3: API server does not validate client-provided intermediate certificates correctly | HIGH | 8.1 | Sep 10, 2018 |
| CVE-2016-8651 | 3: Pulling of any image is possible with it manifest | LOW | 3.5 | Aug 1, 2018 |
| CVE-2016-8631 | 3: Router sometimes selects new routes over old routes when determining claimed hostnames | HIGH | 7.7 | Jul 31, 2018 |
| CVE-2017-12195 | 3: authentication bypass for elasticsearch with external routes | MEDIUM | 6.5 | Jul 27, 2018 |
| CVE-2017-15137 | atomic-openshift: image import whitelist can be bypassed by creating an imagestream or using oc tag | MEDIUM | 5.3 | Jul 16, 2018 |
| CVE-2018-10875 | ansible: ansible.cfg is being read from current working directory allowing possible code execution | HIGH | 8.5 | Jul 13, 2018 |
| CVE-2018-10885 | atomic-openshift: Malicious network-policy can cause Openshift Routing DoS when using ovs-networkpolicy plugin | HIGH | 7.5 | Jul 5, 2018 |
| CVE-2018-1257 | spring-framework: ReDoS Attack with spring-messaging | MEDIUM | 6.5 | May 11, 2018 |
| CVE-2017-2611 | jenkins: Insufficient permission check for periodic processes (SECURITY-389) | MEDIUM | 4.3 | May 8, 2018 |
| CVE-2018-1102 | source-to-image: Improper path sanitization in ExtractTarStreamFromTarReader in tar/tar.go | CRITICAL | 9.9 | Apr 30, 2018 |
| CVE-2018-1059 | dpdk: Information exposure in unchecked guest physical to host virtual address translations | MEDIUM | 6.1 | Apr 24, 2018 |
| CVE-2016-9592 | openshift: Failing to detach a volume causes DoS by retrying to perform delete | MEDIUM | 4.3 | Apr 16, 2018 |
| CVE-2017-7534 | openshift: XSS in log viewer for a pod | MEDIUM | 5.4 | Apr 11, 2018 |
| CVE-2018-1069 | Networking: container networking does not prevent access to network resources | HIGH | 7.1 | Mar 9, 2018 |
| CVE-2013-4364 | OpenShift: openshift-origin-broker-util incorrect temporary file usage | HIGH | 7.8 | Jan 8, 2018 |
| CVE-2015-7501 | apache-commons-collections: InvokerTransformer code execution during deserialisation | CRITICAL | 9.8 | Nov 9, 2017 |
Showing 51 to 75 of 148 CVEs