Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.4% | — | CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux | 7/2/2020 | 17/6/2026 | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT… | |
| Modificada | Crítica (9.8) | 5.5% | — | Redhat Openshift | 28/1/2020 | 16/6/2026 | The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart. | |
| Modificada | Alta (7.5) | 3.6% | — | NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+2 | 27/1/2020 | 17/6/2026 | Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869. | |
| Modificada | Alta (8.8) | 1.1% | — | Redhat Openshift Container Platform | 7/1/2020 | 17/6/2026 | A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged… | |
| Modificada | Media (6.5) | 0.80% | — | Redhat Openshift Container Platform | 7/1/2020 | 17/6/2026 | OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. | |
| Modificada | Media (6.5) | 0.43% | — | Redhat Openshift | 30/12/2019 | 16/6/2026 | A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Crítica (9.8) | 2.0% | — | Puppet Marionette CollectiveRedhat OpenshiftDebian Linux | 13/12/2019 | 17/6/2026 | mcollective has a default password set at install | |
| Modificada | Alta (8.8) | 2.0% | — | Redhat Openshift | 11/12/2019 | 17/6/2026 | Openshift has shell command injection flaws due to unsanitized data being passed into shell commands. | |
| Modificada | Media (6.1) | 1.4% | — | Redhat OpenshiftSencha ConnectOpensuseDebian Linux | 11/12/2019 | 17/6/2026 | node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware | |
| Modificada | Alta (8.8) | 3.9% | — | Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 10/12/2019 | 17/6/2026 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.8) | 2.5% | — | Openshift-origin-controller Project Openshift-origin-controller | 10/12/2019 | 16/6/2026 | rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection | |
| Modificada | Media (6.5) | 2.0% | — | Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform | 5/12/2019 | 17/6/2026 | Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,… | |
| Modificada | Media (5.5) | 0.30% | — | Redhat Openshift | 5/12/2019 | 16/6/2026 | OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS | |
| Modificada | Alta (8.1) | 0.96% | — | Redhat Openshift | 3/12/2019 | 16/6/2026 | OpenShift cartridge allows remote URL retrieval | |
| Modificada | Media (6.5) | 0.99% | — | Redhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user. | |
| Modificada | Media (5) | 0.80% | — | Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform | 25/11/2019 | 17/6/2026 | A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network… | |
| Modificada | Media (5.9) | 1.6% | — | Buildah Project BuildahLibpod Project LibpodRedhat Openshift Container PlatformSkopeo Project Skopeo+2 | 25/11/2019 | 17/6/2026 | The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and… | |
| Modificada | Alta (8.8) | 3.1% | — | InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+3 | 25/11/2019 | 17/6/2026 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application. | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Openshift Origin | 21/11/2019 | 17/6/2026 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. | |
| Modificada | Alta (7.5) | 2.3% | — | Phusion PassengerRedhat Openshift | 19/11/2019 | 16/6/2026 | RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process. | |
| Modificada | Alta (7.8) | 0.40% | — | Redhat Openshift | 15/11/2019 | 17/6/2026 | OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution | |
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Media (6.1) | 0.66% | — | Redhat Openshift Origin | 13/11/2019 | 17/6/2026 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. |