Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.29% | — | Kubernetes Cri-oRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR Power+3 | 25/9/2023 | 17/6/2026 | A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. | |
| Modificada | Alta (8) | 1.6% | — | Kubernetes Kube-apiserverRedhat Openshift Container Platform | 24/9/2023 | 17/6/2026 | An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource beyond what the default is. They would then need to create a new pod or patch one that they already… | |
| Modificada | Media (4.3) | 0.74% | — | KialiRedhat Openshift Service Mesh | 23/9/2023 | 17/6/2026 | A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed. | |
| Modificada | Crítica (9.8) | 0.79% | — | Redhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+1 | 22/9/2023 | 17/6/2026 | A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentially sensitive information in the app server configuration. | |
| Modificada | Media (6.8) | 0.95% | — | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Linuxone+2 | 20/9/2023 | 17/6/2026 | A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user… | |
| Modificada | Alta (8.1) | 1.4% | — | QuarkusRedhat Build OF OptaplannerRedhat Build OF QuarkusRedhat Decision Manager+8 | 20/9/2023 | 4/8/2026 | A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security policy altogether, resulting in unauthorized endpoint access and… | |
| Modificada | Crítica (9.8) | 0.94% | — | Redhat Openshift Data Science | 15/9/2023 | 17/6/2026 | A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposure and other issues. | |
| Modificada | Media (5.3) | 0.21% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 15/9/2023 | 17/6/2026 | The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, which was previously fixed in OCP 4.9.41 and 4.10.12 via RHBA-2022:5433… | |
| Modificada | Alta (7.5) | 1.8% | — | Redhat Build OF QuarkusRedhat Decision ManagerRedhat FuseRedhat Integration Camel K+12 | 14/9/2023 | 17/6/2026 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | |
| Modificada | Media (6.5) | 0.59% | — | Redhat Openshift Logging | 21/8/2023 | 17/6/2026 | A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a token valid for one action to execute other actions as long as the authorization allowing the original action is still cached. | |
| Modificada | Media (5) | 1.3% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 4/8/2023 | 17/6/2026 | A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact… | |
| Modificada | Media (6.1) | 0.56% | — | Jenkins Openshift Login | 12/7/2023 | 17/6/2026 | Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins, allowing attackers to perform phishing attacks. | |
| Modificada | Alta (8.8) | 0.83% | — | Jenkins Openshift Login | 12/7/2023 | 17/6/2026 | Jenkins OpenShift Login Plugin 1.1.0.227.v27e08dfb_1a_20 and earlier does not invalidate the previous session on login. | |
| Modificada | Media (6.1) | 0.63% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM Linuxone+1 | 7/7/2023 | 17/6/2026 | Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri. | |
| Modificada | Alta (7.5) | 0.52% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR LinuxoneRedhat Openshift Container Platform FOR PowerRedhat Openshift Container Platform IBM Z Systems+1 | 5/7/2023 | 17/6/2026 | A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated. | |
| Modificada | Media (6.5) | 0.94% | — | Redhat Openshift API FOR Data ProtectionRedhat Openshift Container PlatformRedhat Openshift Developer Tools AND Services | 6/6/2023 | 17/6/2026 | A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large value for `n,` causing the allocation of a massive string array,… | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Media (5.4) | 0.70% | 💥 PoC | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 29/3/2023 | 17/6/2026 | A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Openshift Assisted InstallerRedhat Openshift Container Platform | 24/3/2023 | 17/6/2026 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. | |
| Modificada | Media (6.5) | 1.8% | — | HaproxyRedhat Ceph StorageRedhat Software CollectionsRedhat Openshift Container Platform+5 | 23/3/2023 | 17/6/2026 | An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability. | |
| Modificada | Alta (7) | 0.45% | — | Linuxfoundation RuncRedhat Openshift Container PlatformRedhat Enterprise LinuxDebian Linux | 3/3/2023 | 17/6/2026 | runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921… | |
| Modificada | Media (6.3) | 0.65% | — | Redhat Openshift | 26/1/2023 | 17/6/2026 | A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is… | |
| Modificada | Media (5.3) | 0.32% | — | Redhat Openshift | 17/1/2023 | 17/6/2026 | The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Even though the CVE-2016-2183 has been fixed in the etcd components, to enable periodic health checks from kubelet, it was necessary to open up a new port (9979) on etcd… | |
| Modificada | Media (5.9) | 0.68% | — | Redhat Openshift Container PlatformRedhat Openshift Osin | 28/12/2022 | 17/6/2026 | A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. The manipulation of the argument secret leads to observable timing discrepancy. The name of the patch is 8612686d6dda34ae9ef6b5a974e4b7accb4fea29. It is recommended to… | |
| Modificada | Alta (7.4) | 0.55% | — | Redhat Openshift | 9/12/2022 | 17/6/2026 | Openshift 4.9 does not use HTTP Strict Transport Security (HSTS) which may allow man-in-the-middle (MITM) attacks. |