Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 62% | — | HaproxyDebian LinuxRedhat Openshift Container PlatformFedoraproject Fedora+2 | 2/4/2020 | 17/6/2026 | In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution. | |
| Modificada | Alta (8.8) | 2.7% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux | 31/3/2020 | 17/6/2026 | A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions. | |
| Modificada | Alta (7.8) | 0.46% | — | Systemd Project SystemdRedhat Ceph StorageRedhat DiscoveryRedhat Migration Toolkit+3 | 31/3/2020 | 17/6/2026 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially… | |
| Modificada | Alta (8.6) | 3.5% | 💥 PoC | KialiRedhat Openshift Service Mesh | 26/3/2020 | 17/6/2026 | A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio… | |
| Modificada | Alta (8.8) | 2.1% | — | Jenkins Openshift Pipeline | 25/3/2020 | 17/6/2026 | Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability. | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Openshift | 20/3/2020 | 17/6/2026 | A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift | 20/3/2020 | 17/6/2026 | A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their… | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Openshift | 20/3/2020 | 17/6/2026 | A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their… | |
| Modificada | Alta (7) | 0.24% | — | Redhat Openshift | 18/3/2020 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift… | |
| Modificada | Alta (7) | 0.25% | — | Redhat Openshift | 18/3/2020 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in… | |
| Modificada | Media (4.4) | 0.33% | — | Redhat Openshift | 18/3/2020 | 17/6/2026 | During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer… | |
| Modificada | Crítica (9.1) | 1.1% | — | Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+2 | 16/3/2020 | 17/6/2026 | A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a… | |
| Modificada | Media (5.3) | 0.61% | — | Jenkins Openshift Deployer | 9/3/2020 | 17/6/2026 | Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Alta (7) | 0.24% | — | Redhat Openshift Container Platform | 9/3/2020 | 17/6/2026 | It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to… | |
| Modificada | Alta (7.5) | 1.9% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 4/3/2020 | 2/10/2026 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when responding internally to pipelined requests. | |
| Modificada | Alta (7.5) | 1.9% | — | Envoyproxy EnvoyRedhat Openshift Service MeshDebian Linux | 4/3/2020 | 2/10/2026 | CNCF Envoy through 1.13.0 may consume excessive amounts of memory when proxying HTTP/1.1 requests or responses with many small (i.e. 1 byte) chunks. | |
| Modificada | Crítica (9.8) | 5.6% | — | Fasterxml Jackson-databindRedhat Decision ManagerRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+4 | 2/3/2020 | 17/6/2026 | A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.2% | — | NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+4 | 19/2/2020 | 16/6/2026 | Nokogiri before 1.5.4 is vulnerable to XXE attacks | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Openshift Service Mesh | 17/2/2020 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the openshift/istio-kialia-rhel7-operator-container. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.5) | 5.1% | — | Gpgme Project GpgmeRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+5 | 12/2/2020 | 17/6/2026 | The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification. | |
| Modificada | Alta (7.3) | 2.6% | — | IstioRedhat Openshift Service Mesh | 12/2/2020 | 17/6/2026 | Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact-path matching logic can allow unauthorized access to HTTP paths even if they are configured to be only accessed after presenting a valid JWT token. For example, an… | |
| Modificada | Alta (7) | 0.43% | — | Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 12/2/2020 | 17/6/2026 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due… | |
| Modificada | Crítica (9.8) | 3.8% | — | Redhat Openshift | 12/2/2020 | 17/6/2026 | The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap… | |
| Modificada | Media (5.9) | 1.8% | — | Libpod Project LibpodRedhat Openshift Container PlatformRedhat Enterprise Linux | 11/2/2020 | 17/6/2026 | A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to… | |
| Modificada | Alta (7) | 0.28% | — | Redhat Openshift Container Platform | 7/2/2020 | 17/6/2026 | It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify… |