Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
790 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Alta (7.5) | 1.1% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Alta (7.5) | 1.2% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Media (5.5) | 0.38% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Media (5.5) | 0.38% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract emails of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Alta (7.5) | 1.2% | — | Rdbrck Shift | 17/7/2019 | 17/6/2026 | Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. | |
| Modificada | Media (4.3) | 1.6% | — | JenkinsRedhat Openshift Container Platform | 17/7/2019 | 17/6/2026 | A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information. | |
| Modificada | Media (5.4) | 0.87% | — | Redhat Openshift Container Platform | 11/7/2019 | 17/6/2026 | A reflected XSS vulnerability exists in authorization flow of OpenShift Container Platform versions: openshift-online-3, openshift-enterprise-3.4 through 3.7 and openshift-enterprise-3.9 through 3.11. An attacker could use this flaw to steal authorization data by getting them to click on a malicious link. | |
| Modificada | Crítica (9.8) | 5.7% | — | Fasterxml Jackson-databindRedhat Openshift Container PlatformOracle ClusterwareOracle Communications Instant Messaging Server+3 | 9/7/2019 | 17/6/2026 | An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6. | |
| Modificada | Crítica (9.8) | 3.0% | — | Redhat UndertowRedhat VirtualizationRedhat Virtualization HostRedhat Jboss Data Grid+2 | 12/6/2019 | 17/6/2026 | A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange) | |
| Modificada | Media (5.9) | 1.4% | — | Redhat Openshift Container Platform | 12/6/2019 | 17/6/2026 | It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output. | |
| Modificada | Alta (8.3) | 3.7% | — | Envoyproxy EnvoyRedhat Openshift Service Mesh | 25/4/2019 | 17/6/2026 | When parsing HTTP/1.x header values, Envoy 1.9.0 and before does not reject embedded zero characters (NUL, ASCII 0x0). This allows remote attackers crafting header values containing embedded NUL characters to potentially bypass header matching rules, gaining access to unauthorized resources. | |
| Modificada | Alta (8.1) | 12% | 💥 Exploit | Oracle JDKOracle JRERedhat Openshift Container PlatformDebian Linux+11 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability… | |
| Modificada | Media (5.9) | 38% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+13 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 4.4% | — | Oracle JDKOracle JRERedhat Openshift Container PlatformRedhat Satellite+12 | 23/4/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9.8) | 1.4% | — | Redhat Openshift Container PlatformHeketi Project Heketi | 22/4/2019 | 17/6/2026 | It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11. | |
| Modificada | Media (5) | 0.50% | — | KubernetesNetapp TridentRedhat Openshift Container Platform | 22/4/2019 | 17/6/2026 | In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is specified and pointed at a different location accessible to other users/groups, the written files may… | |
| Modificada | Media (5.4) | 1.3% | — | JenkinsOracle Communications Cloud Native Core Automated Test SuiteRedhat Openshift Container Platform | 10/4/2019 | 17/6/2026 | The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names. | |
| Modificada | Alta (8.1) | 2.1% | — | JenkinsRedhat Openshift Container PlatformOracle Communications Cloud Native Core Automated Test Suite | 10/4/2019 | 17/6/2026 | Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix for CVE-2019-1003004 in these releases did not reject existing remoting-based CLI authentication… | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+23 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating… | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Openshift Deployer | 4/4/2019 | 17/6/2026 | A missing permission check in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Openshift Deployer | 4/4/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins OpenShift Deployer Plugin in the DeployApplication.DeployApplicationDescriptor#doCheckLogin form validation method allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.3) | 0.67% | — | Redhat Openshift Container Platform | 1/4/2019 | 17/6/2026 | A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a separate XSS vulnerability via JavaScript could further allow for the extraction of these tokens. | |
| Modificada | Media (5.5) | 13% | 💥 PoC | KubernetesRedhat Openshift Container Platform | 1/4/2019 | 17/6/2026 | The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output… | |
| Modificada | Media (6.5) | 11% | — | KubernetesRedhat Openshift Container Platform | 1/4/2019 | 17/6/2026 | In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources… |