Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

698 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.3%—Kubernetes Container Storage Interface Snapshotter21/1/202117/6/2026
Kubernetes CSI snapshot-controller prior to v2.1.3 and v3.0.2 could panic when processing a VolumeSnapshot custom resource when: - The VolumeSnapshot referenced a non-existing PersistentVolumeClaim and the VolumeSnapshot did not reference any VolumeSnapshotClass. - The snapshot-controller crashes, is automatically…
ModificadaCrítica (9.8)4.9%—GrafanaSaml Project SamlRedhat Openshift Container PlatformRedhat Openshift Service Mesh+221/12/202017/6/2026
A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
ModificadaAlta (7.1)0.31%—Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformRedhat Openstack Platform+118/12/202017/6/2026
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all…
ModificadaMedia (6.7)0.48%—Linux KernelRedhat Openshift Container PlatformRedhat Enterprise Linux15/12/202017/6/2026
A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running…
ModificadaAlta (7.8)1.7%💥 PoCLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise MRG+211/12/202017/6/2026
A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow…
ModificadaAlta (8.8)2.0%—Katacontainers Kata Containers7/12/202017/6/2026
An issue was discovered in Kata Containers through 1.11.3 and 2.x through 2.0-rc1. The runtime will execute binaries given using annotations without any kind of validation. Someone who is granted access rights to a cluster will be able to have kata-runtime execute arbitrary binaries as root on the worker nodes.
ModificadaMedia (6.1)0.65%—Elastic KibanaRedhat Openshift Container Platform2/12/202017/6/2026
The elasticsearch-operator does not validate the namespace where kibana logging resource is created and due to that it is possible to replace the original openshift-logging console link (kibana console) to different one, created based on the new CR for the new kibana resource. This could lead to an arbitrary URL…
ModificadaMedia (5.2)3.2%💥 PoCLinuxfoundation ContainerdFedoraproject FedoraDebian Linux1/12/202017/6/2026
containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an…
ModificadaMedia (5.5)0.42%—Heketi Project HeketiRedhat Gluster StorageRedhat Openshift Container PlatformRedhat Enterprise Linux24/11/202017/6/2026
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords.
ModificadaAlta (8.8)1.0%—Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora23/11/202017/6/2026
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a…
ModificadaAlta (7.1)0.37%—Katacontainers Kata-containers17/11/202017/6/2026
An improper file permissions vulnerability affects Kata Containers prior to 1.11.5. When using a Kubernetes hostPath volume and mounting either a file or directory into a container as readonly, the file/directory is mounted as readOnly inside the container, but is still writable inside the guest. For a container…
ModificadaMedia (5.4)0.67%—IBM APP Connect Enterprise Certified Container3/11/202017/6/2026
IBM App Connect Enterprise Certified Container 1.0.0, 1.0.1, 1.0.2, 1.0.3, and 1.0.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly…
ModificadaMedia (6.5)0.86%—HP Bluedata EpicHP Ezmeral Container Platform26/10/202017/6/2026
The HPE BlueData EPIC Software Platform version 4.0 and HPE Ezmeral Container Platform 5.0 use an insecure method of handling sensitive Kerberos passwords that is susceptible to unauthorized interception and/or retrieval. Specifically, they display the kdc_admin_password in the source file of the url…
ModificadaMedia (6.1)2.3%—Linuxfoundation ContainerdCanonical Ubuntu LinuxDebian Linux16/10/202017/6/2026
In containerd (an industry-standard container runtime) before version 1.2.14 there is a credential leaking vulnerability. If a container image manifest in the OCI Image format or Docker Image V2 Schema 2 format includes a URL for the location of a specific image layer (otherwise known as a “foreign layer”), the…
ModificadaMedia (5.3)1.4%—Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora23/9/202017/6/2026
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent…
ModificadaMedia (6.4)1.6%—GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+1129/7/202017/6/2026
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of…
ModificadaMedia (6.4)0.98%—GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+1029/7/202017/6/2026
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and…
ModificadaMedia (6.4)1.4%—GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+1029/7/202017/6/2026
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects…
ModificadaAlta (8.8)0.32%—DockerRedhat Openshift Container PlatformRedhat Enterprise Linux Server13/7/202017/6/2026
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and…
ModificadaAlta (7.5)1.1%—Redhat Openshift Container Platform12/6/202017/6/2026
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the logs, and use the leaked OAuthToken to log into the API Server with…
ModificadaAlta (8.8)0.47%—Katacontainers RuntimeFedoraproject Fedora10/6/202017/6/2026
A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path, potentially allowing for code execution on the host. This issue affects: Kata Containers 1.11…
ModificadaMedia (6.3)1.1%💥 PoCKatacontainers Runtime10/6/202017/6/2026
Kata Containers doesn't restrict containers from accessing the guest's root filesystem device. Malicious containers can exploit this to gain code execution on the guest and masquerade as the kata-agent. This issue affects Kata Containers 1.11 versions earlier than 1.11.1; Kata Containers 1.10 versions earlier than…
ModificadaAlta (7.2)2.1%—Elastic KibanaRedhat Openshift Container Platform3/6/202017/6/2026
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead to an attacker executing code with the permissions of the Kibana…
ModificadaMedia (6)2.4%💥 PoCLinuxfoundation CNI Network PluginsRedhat Openshift Container PlatformFedoraproject FedoraRedhat Enterprise Linux3/6/202017/6/2026
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to…
ModificadaAlta (8.8)0.31%—Katacontainers Runtime19/5/202017/6/2026
Kata Containers before 1.11.0 on Cloud Hypervisor persists guest filesystem changes to the underlying image file on the host. A malicious guest can overwrite the image file to gain control of all subsequent guest VMs. Since Kata Containers uses the same VM image file with all VMMs, this issue may also affect QEMU and…
Orbitaley — Vulnerabilidades