Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

790 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.82%—Redhat KeycloakRedhat Openshift Application RuntimesRedhat Single Sign-on11/5/202017/6/2026
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
ModificadaMedia (4.2)0.66%—Redhat SoteriaRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Openshift Application Runtimes4/5/202017/6/2026
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
ModificadaAlta (8.6)1.2%—KialiRedhat Openshift Service Mesh27/4/202017/6/2026
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
ModificadaMedia (5.9)0.88%—Redhat Openshift Container Platform24/4/202017/6/2026
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing…
ModificadaMedia (6.1)1.6%—Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+223/4/202017/6/2026
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
ModificadaAlta (8.2)0.99%—Redhat Openshift Container Platform22/4/202017/6/2026
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is…
ModificadaAlta (8.1)1.6%—Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss Fuse+221/4/202017/6/2026
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping…
ModificadaMedia (6.8)1.6%—Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+113/4/202017/6/2026
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a…
ModificadaAlta (7)0.26%—Redhat Openshift2/4/202017/6/2026
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
ModificadaAlta (7)0.26%—Redhat Openshift2/4/202017/6/2026
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
ModificadaAlta (8.8)62%—HaproxyDebian LinuxRedhat Openshift Container PlatformFedoraproject Fedora+22/4/202017/6/2026
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
ModificadaAlta (8.8)2.7%—Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux31/3/202017/6/2026
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
ModificadaAlta (7.8)0.46%—Systemd Project SystemdRedhat Ceph StorageRedhat DiscoveryRedhat Migration Toolkit+331/3/202017/6/2026
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially…
ModificadaAlta (8.6)3.5%💥 PoCKialiRedhat Openshift Service Mesh26/3/202017/6/2026
A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass Kiali authentication mechanisms, possibly gaining privileges to view and alter the Istio…
ModificadaAlta (8.8)2.1%—Jenkins Openshift Pipeline25/3/202017/6/2026
Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaAlta (7.8)0.27%—Redhat Openshift20/3/202017/6/2026
A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the openshift/mediawiki. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.
ModificadaAlta (7)0.26%—Redhat Openshift20/3/202017/6/2026
A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/postgresql-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their…
ModificadaAlta (7.8)0.27%—Redhat Openshift20/3/202017/6/2026
A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mediawiki-apb. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their…
ModificadaAlta (7)0.24%—Redhat Openshift18/3/202017/6/2026
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/ansible-operator-container as shipped in Openshift…
ModificadaAlta (7)0.25%—Redhat Openshift18/3/202017/6/2026
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges. This CVE is specific to the openshift/jenkins-slave-base-rhel7-containera as shipped in…
ModificadaMedia (4.4)0.33%—Redhat Openshift18/3/202017/6/2026
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift API server, and are incorrectly assigned word-readable permissions. ose-installer…
ModificadaCrítica (9.1)1.1%—Redhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Jboss FuseRedhat Openshift Application Runtimes+216/3/202017/6/2026
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a…
ModificadaMedia (5.3)0.61%—Jenkins Openshift Deployer9/3/202017/6/2026
Jenkins OpenShift Deployer Plugin 1.2.0 and earlier transmits configured credentials in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure.
ModificadaAlta (7)0.24%—Redhat Openshift Container Platform9/3/202017/6/2026
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to…
ModificadaAlta (7)0.28%—Timeshift Project TimeshiftFedoraproject FedoraCanonical Ubuntu Linux5/3/202017/6/2026
init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can…
Orbitaley — Vulnerabilidades