Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
645 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 82% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU. | |
| Modificada | Alta (7.5) | 60% | 💥 PoC | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipulate window size and stream priority to force the server to… | |
| Modificada | Media (5.4) | 0.55% | — | Redhat Openshift Container Platform | 2/8/2019 | 17/6/2026 | A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack. | |
| Modificada | Media (5.4) | 0.62% | — | Redhat Openshift | 1/8/2019 | 17/6/2026 | A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8, 3.9, 3.10, 3.11 and 4.1 are affected. | |
| Modificada | Media (4.3) | 1.2% | — | Jenkins Pipeline\Redhat Openshift Container Platform | 31/7/2019 | 17/6/2026 | A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by global libraries. | |
| Modificada | Alta (8.8) | 2.5% | — | Jenkins Script SecurityRedhat Openshift Container Platform | 31/7/2019 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts. | |
| Modificada | Alta (8.8) | 2.5% | — | Jenkins Script SecurityRedhat Openshift Container Platform | 31/7/2019 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts. | |
| Modificada | Baja (2.3) | 0.38% | — | Redhat Openshift Container Platform | 30/7/2019 | 17/6/2026 | OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens from these audit logs and use them to access other resources. | |
| Modificada | Crítica (9.8) | 8.1% | — | Fasterxml Jackson-databindDebian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation+20 | 29/7/2019 | 17/6/2026 | SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution. | |
| Modificada | Alta (7.5) | 3.5% | — | Redhat UndertowRedhat Jboss Data GridRedhat Jboss Enterprise Application PlatformRedhat Openshift Application Runtimes+2 | 25/7/2019 | 17/6/2026 | undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api. | |
| Modificada | Crítica (9.8) | 6.3% | — | Gnome PangoOracle Sd-wan EdgeFedoraproject FedoraDebian Linux+9 | 19/7/2019 | 17/6/2026 | Gnome Pango 1.42 and later is affected by: Buffer Overflow. The impact is: The heap based buffer overflow can be used to get code execution. The component is: function name: pango_log2vis_get_embedding_levels, assignment of nchars and the loop condition. The attack vector is: Bug can be used when application pass… | |
| Modificada | Media (4.3) | 1.6% | — | JenkinsRedhat Openshift Container Platform | 17/7/2019 | 17/6/2026 | A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information. | |
| Modificada | Media (5.4) | 0.87% | — | Redhat Openshift Container Platform | 11/7/2019 | 17/6/2026 | A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link. | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindRedhat Openshift Container PlatformOracle ClusterwareOracle Communications Instant Messaging Server+3 | 9/7/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. | |
| Modificada | Crítica (9.8) | 3.0% | — | Redhat UndertowRedhat VirtualizationRedhat Virtualization HostRedhat Jboss Data Grid+2 | 12/6/2019 | 17/6/2026 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange) | |
| Modificada | Media (5.9) | 1.4% | — | Redhat Openshift Container Platform | 12/6/2019 | 17/6/2026 | It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output. | |
| Modificada | Alta (8.3) | 3.7% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 25/4/2019 | 17/6/2026 | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources. | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | Oracle JDKOracle JRERedhat Openshift Container PlatformDebian Linux+11 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Media (5.9) | 38% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+13 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 4.4% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+12 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9.8) | 1.4% | — | Redhat Openshift Container PlatformHeketi Project Heketi | 22/4/2019 | 17/6/2026 | It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11. | |
| Modificada | Media (5) | 0.50% | — | KubernetesNetapp TridentRedhat Openshift Container Platform | 22/4/2019 | 17/6/2026 | In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may… | |
| Modificada | Media (5.4) | 1.3% | — | JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform | 10/4/2019 | 17/6/2026 | The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names. | |
| Modificada | Alta (8.1) | 2.1% | — | JenkinsRedhat Openshift Container PlatformOracle Communications Cloud Native Core Automated Test Suite | 10/4/2019 | 17/6/2026 | Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication… | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+23 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating… |