Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
649 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.26% | — | Redhat Openshift Service MeshAIEnvoyproxy EnvoyAI | 28/1/2025 | 17/6/2026 | The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and… | |
| Modificada | Alta (7.1) | 0.41% | — | Redhat Openshift Service Mesh | 28/1/2025 | 17/6/2026 | A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy. | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Media (6.8) | 1.8% | — | Samba RsyncRedhat Openshift Container PlatformRedhat Enterprise LinuxAlmalinux+5 | 14/1/2025 | 21/8/2026 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Aplazada | Alta (8.8) | 0.49% | — | Redhat Openshift DedicatedAIRedhat HiveAI | 31/12/2024 | 17/6/2026 | A flaw was found in the Hive ClusterDeployments resource in OpenShift Dedicated. In certain conditions, this issue may allow a developer account on a Hive-enabled cluster to obtain cluster-admin privileges by executing arbitrary commands on the hive/hive-controllers pod. | |
| Aplazada | Alta (7.6) | 0.58% | — | OpenshiftAI | 31/12/2024 | 21/9/2026 | A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not… | |
| Aplazada | Alta (8.8) | 0.76% | — | Redhat Openshift DedicatedAI | 19/12/2024 | 17/6/2026 | A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially crafted file and set the most privileged service account to run the job. This can allow a standard developer user to… | |
| Aplazada | Media (5.3) | 0.58% | — | Openshift ConsoleAI | 25/11/2024 | 17/6/2026 | A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network position and can often reach exposed services that aren't readily available to clients due to network… | |
| Modificada | Media (5.3) | 0.56% | — | Redhat Openshift Container Platform | 22/10/2024 | 11/8/2026 | A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retrieve a comprehensive list of available queries and mutations. Exposure to this flaw increases the attack surface, as it can facilitate the discovery of flaws or errors… | |
| Modificada | Media (6.5) | 0.60% | — | Redhat Openshift Container Platform | 22/10/2024 | 17/6/2026 | A denial of service (DoS) vulnerability was found in OpenShift. This flaw allows attackers to exploit the GraphQL batching functionality. The vulnerability arises when multiple queries can be sent within a single request, enabling an attacker to submit a request containing thousands of aliases in one query. This issue… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+11 | 15/10/2024 | 17/6/2026 | A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in… | |
| Modificada | Media (4.4) | 0.39% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 9/10/2024 | 7/8/2026 | A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by… | |
| Modificada | Alta (8.2) | 1.0% | — | Containers CommonRedhat Openshift Container PlatformRedhat Enterprise Linux | 1/10/2024 | 11/8/2026 | A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a… | |
| Modificada | Media (6.1) | 2.1% | 💥 Exploit | Redhat Build OF KeycloakRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+2 | 19/9/2024 | 4/8/2026 | A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session… | |
| Aplazada | Crítica (9.1) | 2.3% | — | Openshift BuilderAI | 17/9/2024 | 11/8/2026 | A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden… | |
| Aplazada | Crítica (9.9) | 1.0% | — | Openshift Container PlatformAI | 17/9/2024 | 11/8/2026 | A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with… | |
| Modificada | Media (6.5) | 0.79% | — | Redhat KeycloakRedhat Build OF KeycloakRedhat Single Sign-onRedhat Openshift Container Platform+3 | 3/9/2024 | 17/6/2026 | A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole… | |
| Aplazada | Alta (8) | 0.67% | — | Openshift ConsoleAI | 21/8/2024 | 11/8/2026 | An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application… | |
| Modificada | Alta (8.8) | 0.93% | — | Redhat Openshift AIRedhat Openshift Data Science | 12/8/2024 | 17/6/2026 | A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. However, credentials from one model can be used to access other models and APIs… | |
| Modificada | Media (4.8) | 0.55% | — | Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 2/8/2024 | 17/6/2026 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is… | |
| Aplazada | Media (5.3) | 0.42% | — | Openshift ConsoleAI | 26/7/2024 | 17/6/2026 | A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider ("openShiftAuth") is set, these functions do not perform any authentication checks, relying instead on the targeted service to… | |
| Modificada | Media (6.5) | 0.36% | — | Redhat Openshift Container Platform | 24/7/2024 | 17/6/2026 | A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI that is remote HTTP/HTTPS or local. Access to this endpoint is gated by the authHandlerWithUser() middleware function. Contrary to its name, this middleware function does… | |
| Modificada | Alta (8.1) | 100% | 💥 Exploit | Sonicwall SMA 6200 FirmwareSonicwall SMA 7200 FirmwareArista EOSCanonical Ubuntu Linux+49 | 1/7/2024 | 1/9/2026 | A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period. | |
| Modificada | Alta (8.1) | 1.2% | — | Kubernetes Cri-oRedhat Openshift Container Platform | 12/6/2024 | 21/8/2026 | A flaw was found in cri-o. A malicious container can create a symbolic link to arbitrary files on the host via directory traversal (“../“). This flaw allows the container to read and write to arbitrary files on the host system. |