Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.74% | — | Redhat Openshift | 8/12/2022 | 17/6/2026 | A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability. | |
| Modificada | Media (4.8) | 0.44% | — | Redhat Openshift | 8/12/2022 | 17/6/2026 | The response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these results incorrectly, allowing clickjacking attacks. | |
| Modificada | Media (5.5) | 0.21% | — | Redhat Openshift | 19/10/2022 | 16/6/2026 | In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file. | |
| Modificada | Alta (7.5) | 0.65% | — | Redhat Openshift | 19/10/2022 | 16/6/2026 | The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file. | |
| Modificada | Baja (3.5) | 0.50% | — | Redhat Openshift | 17/10/2022 | 17/6/2026 | An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored… | |
| Modificada | Alta (7.1) | 0.35% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux | 13/9/2022 | 17/6/2026 | An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary… | |
| Modificada | Alta (7.1) | 0.32% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux | 13/9/2022 | 17/6/2026 | An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code… | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Openshift | 1/9/2022 | 17/6/2026 | A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the… | |
| Modificada | Media (6.3) | 0.58% | — | Redhat Openshift Container Platform | 1/9/2022 | 17/6/2026 | In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary… | |
| Modificada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformRedhat Openshift Container PlatformFedoraproject Fedora | 1/9/2022 | 17/6/2026 | An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality. | |
| Modificada | Alta (8.6) | 2.2% | — | Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+4 | 31/8/2022 | 17/6/2026 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. | |
| Modificada | Alta (7.5) | 1.6% | — | Redhat Openshift Application RuntimesRedhat Single Sign-onRedhat UndertowNetapp Active IQ Unified Manager+3 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet… | |
| Modificada | Alta (7.5) | 1.3% | — | Redhat Build OF QuarkusRedhat Integration Camel KRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+6 | 31/8/2022 | 17/6/2026 | A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629. | |
| Modificada | Media (4.9) | 1.7% | — | Openstack Oslo.utilsRedhat Openshift Container PlatformRedhat Openstack PlatformDebian Linux | 29/8/2022 | 17/6/2026 | A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. | |
| Modificada | Media (6.5) | 0.30% | — | Dpdk Data Plane Development KITOpenvswitchRedhat Openshift Container Platform | 29/8/2022 | 17/6/2026 | A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sending such messages continuously, the vhost-user master exhausts… | |
| Modificada | Alta (7.5) | 0.82% | — | Redhat Openshift Serverless | 26/8/2022 | 17/6/2026 | It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0. | |
| Modificada | Media (5.5) | 0.29% | — | Linux KernelIBM Spectrum Copy Data ManagementIBM Spectrum Protect PlusDebian Linux+19 | 26/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS. | |
| Modificada | Media (6.5) | 0.56% | — | Redhat Ceph StorageRedhat Openshift Container StorageRedhat Openshift Data FoundationRedhat Openstack Platform+3 | 25/8/2022 | 17/6/2026 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks. | |
| Modificada | Media (6.1) | 0.51% | — | Redhat Build OF QuarkusRedhat Openshift Application RuntimesRedhat Smallrye Health | 25/8/2022 | 17/6/2026 | It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks. | |
| Modificada | Media (6.7) | 0.33% | 💥 PoC | Redhat Fabric8-kubernetesRedhat A-mq StreamsRedhat Build OF QuarkusRedhat Descision Manager+5 | 24/8/2022 | 17/6/2026 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML. | |
| Modificada | Alta (8.1) | 1.5% | — | Redhat Openshift | 24/8/2022 | 17/6/2026 | It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6. | |
| Modificada | Media (6.8) | 1.1% | — | Redhat KeycloakRedhat Single Sign-onRedhat Openshift Container Platform | 23/8/2022 | 17/6/2026 | A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this… | |
| Modificada | Alta (7.5) | 1.7% | — | Redhat FuseRedhat Integration Camel KRedhat Integration Camel QuarkusRedhat Jboss Enterprise Application Platform+3 | 23/8/2022 | 17/6/2026 | A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability. | |
| Modificada | Crítica (9.8) | 1.0% | — | Redhat Openshift Service MeshRedhat Servicemesh-operator | 22/8/2022 | 17/6/2026 | A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allowing access to all ports on these resources from any pod. The highest threat from this vulnerability is to data confidentiality and integrity as well as system… | |
| Modificada | Media (5.4) | 0.49% | — | Redhat Openshift API Management | 22/8/2022 | 17/6/2026 | A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into some text boxes leading to a XSS attack. The highest threat from this vulnerability is to data confidentiality. |