Lucene search

K

Atomic-openshift Security Vulnerabilities

cve
cve

CVE-2019-10225

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and...

6.3CVSS

6.2AI Score

0.001EPSS

2021-03-19 09:15 PM
49
5
cve
cve

CVE-2020-15705

GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim....

6.4CVSS

6.8AI Score

0.001EPSS

2020-07-29 06:15 PM
253
3
cve
cve

CVE-2020-15706

GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2....

6.4CVSS

7.4AI Score

0.002EPSS

2020-07-29 06:15 PM
243
2
cve
cve

CVE-2020-15707

Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an...

6.4CVSS

7.6AI Score

0.001EPSS

2020-07-29 06:15 PM
277
cve
cve

CVE-2019-10176

A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to...

5.4CVSS

5.4AI Score

0.001EPSS

2019-08-02 03:15 PM
144
cve
cve

CVE-2019-3884

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are...

5.4CVSS

5.5AI Score

0.001EPSS

2019-08-01 02:15 PM
57
cve
cve

CVE-2019-3889

A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a...

5.4CVSS

5AI Score

0.001EPSS

2019-07-11 07:15 PM
56
cve
cve

CVE-2019-10150

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build...

5.9CVSS

5.8AI Score

0.008EPSS

2019-06-12 02:29 PM
57
cve
cve

CVE-2018-14632

An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster...

7.7CVSS

7.1AI Score

0.002EPSS

2018-09-06 02:29 PM
55
cve
cve

CVE-2017-15138

The OpenShift Enterprise cluster-read can access webhook tokens which would allow an attacker with sufficient privileges to view confidential webhook...

5CVSS

5AI Score

0.001EPSS

2018-08-13 05:29 PM
38
cve
cve

CVE-2017-15137

The OpenShift image import whitelist failed to enforce restrictions correctly when running commands such as "oc tag", for example. This could allow a user with access to OpenShift to run images from registries that should not be...

5.3CVSS

5.3AI Score

0.001EPSS

2018-07-16 08:29 PM
38
cve
cve

CVE-2018-10885

In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9, or 3.7...

7.5CVSS

7.3AI Score

0.001EPSS

2018-07-05 01:29 PM
33
cve
cve

CVE-2018-1102

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege...

8.8CVSS

8.4AI Score

0.004EPSS

2018-04-30 07:29 PM
94