Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

698 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.37%—Katacontainers Runtime19/5/202017/6/2026
An improper link resolution vulnerability affects Kata Containers versions prior to 1.11.0. Upon container teardown, a malicious guest can trick the kata-runtime into unmounting any mount point on the host and all mount points underneath it, potentiality resulting in a host DoS.
ModificadaMedia (6.6)0.13%—Redhat Openshift Container Platform12/5/202017/6/2026
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluster as any user who logged into the cluster via the WebUI or via the…
ModificadaMedia (5.9)0.88%—Redhat Openshift Container Platform24/4/202017/6/2026
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and the openshift console, could use this flaw to perform a phishing…
ModificadaMedia (6.1)1.6%—Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+223/4/202017/6/2026
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
ModificadaAlta (8.2)0.99%—Redhat Openshift Container Platform22/4/202017/6/2026
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and write to the storage backing the internal image registry. The highest threat from this vulnerability is…
ModificadaAlta (8.8)62%—HaproxyDebian LinuxRedhat Openshift Container PlatformFedoraproject Fedora+22/4/202017/6/2026
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
ModificadaAlta (8.8)2.7%—Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux31/3/202017/6/2026
A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's system anywhere that the user has permissions.
ModificadaAlta (7.8)0.46%—Systemd Project SystemdRedhat Ceph StorageRedhat DiscoveryRedhat Migration Toolkit+331/3/202017/6/2026
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially…
ModificadaAlta (8.8)2.0%—Jenkins Azure Container Service25/3/202017/6/2026
Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
ModificadaAlta (7)0.24%—Redhat Openshift Container Platform9/3/202017/6/2026
It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify /etc/passwd to…
ModificadaCrítica (9.8)5.6%—Fasterxml Jackson-databindRedhat Decision ManagerRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+42/3/202017/6/2026
A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.
ModificadaAlta (7.5)5.1%—Gpgme Project GpgmeRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+512/2/202017/6/2026
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signature verification.
ModificadaAlta (7)0.43%—Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+112/2/202017/6/2026
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due…
ModificadaMedia (5.9)1.8%—Libpod Project LibpodRedhat Openshift Container PlatformRedhat Enterprise Linux11/2/202017/6/2026
A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container based on a malicious image with an attached volume that is used for the first time, it is possible to…
ModificadaAlta (8.1)1.5%—Linuxcontainers LXC10/2/202017/6/2026
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.
ModificadaAlta (7)0.28%—Redhat Openshift Container Platform7/2/202017/6/2026
It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers modify the permissions of /etc/passwd to make them modifiable by users other than root. An attacker with access to the running container can exploit this to modify…
ModificadaMedia (6.5)2.4%—CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux7/2/202017/6/2026
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT…
ModificadaAlta (8.8)1.1%—Redhat Openshift Container Platform7/1/202017/6/2026
A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw can allow an unprivileged user to escalate their privileges to those allowed by the privileged…
ModificadaMedia (6.5)0.80%—Redhat Openshift Container Platform7/1/202017/6/2026
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
ModificadaAlta (8.8)3.9%—Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+1110/12/201917/6/2026
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)2.0%—Kubernetes External-provisionerKubernetes External-resizerKubernetes External-snapshotterRedhat Openshift Container Platform5/12/201917/6/2026
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot,…
ModificadaMedia (6.5)0.99%—Redhat Openshift Container Platform25/11/201917/6/2026
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret material if the log level has already been modified in an operator by a privileged user.
ModificadaMedia (5)0.80%—Kubernetes Cri-oFedoraproject FedoraRedhat Openshift Container Platform25/11/201917/6/2026
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network…
ModificadaMedia (5.9)1.6%—Buildah Project BuildahLibpod Project LibpodRedhat Openshift Container PlatformSkopeo Project Skopeo+225/11/201917/6/2026
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and…
ModificadaMedia (6.5)0.85%—Jenkins Anchore Container Image Scanner21/11/201917/6/2026
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
Orbitaley — Vulnerabilidades