Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
790 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Storage Project StorageRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 1/4/2021 | 17/6/2026 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the… | |
| Modificada | Alta (7.8) | 0.28% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.33% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7) | 0.26% | — | Redhat Openshift Container Platform | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.8) | 0.34% | — | Redhat Openshift | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.8) | 0.34% | — | Redhat Openshift | 24/3/2021 | 17/6/2026 | An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. | |
| Modificada | Alta (7.5) | 2.8% | — | PygmentsRedhat Openshift Container PlatformRedhat Openstack PlatformRedhat Software Collections+3 | 23/3/2021 | 17/6/2026 | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword. | |
| Modificada | Media (6.3) | 0.59% | — | Redhat OpenshiftRedhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker with basic-user permissions is able to obtain the value of restuserkey, and use it to authenticate… | |
| Modificada | Alta (7.2) | 1.3% | — | Redhat Openshift Container Platform | 19/3/2021 | 17/6/2026 | A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, running on master nodes, can retrieve security credentials for the master AWS IAM role, allowing… | |
| Modificada | Alta (7.5) | 3.2% | — | Lldpd Project LldpdOpenvswitchRedhat Openshift Container PlatformRedhat Openstack+13 | 18/3/2021 | 17/6/2026 | A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability. | |
| Modificada | Alta (8.8) | 1.2% | — | Redhat Openshift BuilderRedhat Openshift Container Platform | 16/3/2021 | 17/6/2026 | A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execute code during build time inside this container can re-use the credentials to overwrite arbitrary… | |
| Modificada | Alta (7.4) | 1.3% | — | Redhat Kubernetes-clientRedhat A-mq OnlineRedhat Build OF QuarkusRedhat Codeready Studio+5 | 16/3/2021 | 17/6/2026 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest threat from this vulnerability is to integrity and system… | |
| Modificada | Media (4.4) | 0.37% | — | Linux KernelFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1 | 4/3/2021 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system. | |
| Modificada | Alta (7.8) | 0.40% | — | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise Linux | 23/2/2021 | 17/6/2026 | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set, and BPF hook to getsockopt is registered). As result of BPF execution, the local user can trigger… | |
| Modificada | Alta (8.8) | 1.1% | — | Redhat Openshift Container Platform | 23/2/2021 | 17/6/2026 | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container, they can potentially utilize the raw devices of the underlying node, such as the network and… | |
| Modificada | Alta (7.5) | 1.4% | — | Redhat Jboss FuseRedhat Openshift Application RuntimesRedhat Undertow | 23/2/2021 | 17/6/2026 | A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow… | |
| Modificada | Alta (8.1) | 1.8% | — | Redhat Openshift Installer | 23/2/2021 | 17/6/2026 | A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during… | |
| Modificada | Alta (7) | 0.26% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux | 11/2/2021 | 17/6/2026 | A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access any other file in the container, even if owned by the root user inside the container. It does not… | |
| Modificada | Baja (2.7) | 0.77% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. | |
| Modificada | Baja (3.3) | 0.21% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable. | |
| Modificada | Media (6.5) | 1.3% | — | IstioRedhat Openshift Service Mesh | 29/1/2021 | 17/6/2026 | A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the Go runtime to panic (resulting in a denial of service to the istio-pilot application). | |
| Modificada | Crítica (9.8) | 4.9% | — | GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+2 | 21/12/2020 | 17/6/2026 | A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformRedhat Openstack Platform+1 | 18/12/2020 | 17/6/2026 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all… | |
| Modificada | Media (6.7) | 0.48% | — | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise Linux | 15/12/2020 | 17/6/2026 | A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running… | |
| Modificada | Alta (7.8) | 1.7% | 💥 PoC | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise MRG+2 | 11/12/2020 | 17/6/2026 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow… |