Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

645 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.4%—CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux7/2/202017/6/2026
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT…
ModificadaCrítica (9.8)5.5%—Redhat Openshift28/1/202016/6/2026
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
ModificadaAlta (7.5)3.6%—NettyFedoraproject FedoraDebian LinuxRedhat Jboss Enterprise Application Platform+227/1/202017/6/2026
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
ModificadaAlta (8.8)1.1%—Redhat Openshift Container Platform7/1/202017/6/2026
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged…
ModificadaMedia (6.5)0.80%—Redhat Openshift Container Platform7/1/202017/6/2026
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
ModificadaMedia (6.5)0.43%—Redhat Openshift30/12/201916/6/2026
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Authorization: header when requesting the REST API via web browser.
ModificadaMedia (6.1)4.0%💥 PoCSmartbear Swagger-uiRedhat Jboss FuseRedhat Openshift20/12/201917/6/2026
swagger-ui has XSS in key names
ModificadaCrítica (9.8)2.0%—Puppet Marionette CollectiveRedhat OpenshiftDebian Linux13/12/201917/6/2026
mcollective has a default password set at install
ModificadaAlta (8.8)2.0%—Redhat Openshift11/12/201917/6/2026
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
ModificadaMedia (6.1)1.4%—Redhat OpenshiftSencha ConnectOpensuseDebian Linux11/12/201917/6/2026
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.8)2.5%—Openshift-origin-controller Project Openshift-origin-controller10/12/201916/6/2026
rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
ModificadaMedia (6.5)2.0%—Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform5/12/201917/6/2026
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,…
ModificadaMedia (5.5)0.30%—Redhat Openshift5/12/201916/6/2026
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
ModificadaAlta (8.1)0.96%—Redhat Openshift3/12/201916/6/2026
OpenShift cartridge allows remote URL retrieval
ModificadaMedia (6.5)0.99%—Redhat Openshift Container Platform25/11/201917/6/2026
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
ModificadaMedia (5)0.80%—Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform25/11/201917/6/2026
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network…
ModificadaMedia (5.9)1.6%—Buildah Project BuildahLibpod Project LibpodRedhat Openshift Container PlatformSkopeo Project Skopeo+225/11/201917/6/2026
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and…
ModificadaAlta (8.8)3.1%—InfinispanRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+325/11/201917/6/2026
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
ModificadaMedia (5.5)0.31%—Redhat Openshift Origin21/11/201917/6/2026
Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly.
ModificadaAlta (7.5)2.3%—Phusion PassengerRedhat Openshift19/11/201916/6/2026
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
ModificadaAlta (7.8)0.40%—Redhat Openshift15/11/201917/6/2026
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
ModificadaMedia (6.5)0.92%—Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+77414/11/201917/6/2026
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
ModificadaMedia (6.1)0.66%—Redhat Openshift Origin13/11/201917/6/2026
OpenShift Origin: Improperly validated team names could allow stored XSS attacks
ModificadaMedia (6.1)2.2%💥 PoCRedhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+1838/11/201925/8/2026
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Orbitaley — Vulnerabilidades