« Volver al listado

Openshift

Openshift Console: vulnerabilidades y CVE

Openshift Console tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses5
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-75887Alta (7.5)0.41%—23 sept 2026
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows…
CVE-2026-75886Alta (7.2)0.32%—23 sept 2026
A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the CatalogdHandler, which lacks proper authentication, and the forwarding of the `openshift-session-token`…
CVE-2026-75885Crítica (9.3)0.69%—18 sept 2026
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side…
CVE-2026-50237Alta (7.4)0.47%—11 ago 2026
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches…
CVE-2026-50236Alta (7.4)0.47%—11 ago 2026
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint…
CVE-2024-6538Media (5.3)0.58%—25 nov 2024
A flaw was found in OpenShift Console. A Server Side Request Forgery (SSRF) attack can happen if an attacker supplies all or part of a URL to the server to query. The server is considered to be in a privileged network…
CVE-2024-7128Media (5.3)0.42%—26 jul 2024
A flaw was found in the OpenShift console. Several endpoints in the application use the authHandler() and authHandlerWithUser() middleware functions. When the default authentication provider ("openShiftAuth") is set,…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1090 Proxy3
  2. T1190 Exploit Public-Facing Application3
  3. T1210 Exploitation of Remote Services2
  4. T1005 Data from Local System1
  5. T1552.007 Container API1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Openshift