Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3037▲ 502 respecto a la semana anterior
Críticas / altas1448▲ 249 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 158 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | Redhat Openshift-origin-node-util | 30/6/2022 | 17/6/2026 | It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | |
| Modificada | Crítica (9.8) | 2.5% | — | Openshift-origin-controller Project Openshift-origin-controller | 10/12/2019 | 16/6/2026 | rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection | |
| Modificada | Media (5.5) | 0.31% | — | Redhat Openshift Origin | 21/11/2019 | 17/6/2026 | Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. | |
| Modificada | Media (6.1) | 0.66% | — | Redhat Openshift Origin | 13/11/2019 | 17/6/2026 | OpenShift Origin: Improperly validated team names could allow stored XSS attacks | |
| Modificada | Baja (3.3) | 0.35% | — | Redhat OpenshiftRedhat Openshift Origin | 8/6/2016 | 17/6/2026 | HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cookie. | |
| Modificada | Alta (8.8) | 4.1% | — | Redhat Openshift OriginRedhat Openshift | 8/6/2016 | 17/6/2026 | Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder image. | |
| Modificada | Media (4) | 2.0% | — | Redhat Openshift Origin | 8/9/2015 | 17/6/2026 | The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data. | |
| Modificada | Alta (10) | 5.2% | — | Redhat OpenshiftRedhat Openshift Origin | 20/6/2014 | 17/6/2026 | cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending with a (1) .tar.gz, (2) .zip, (3) .tgz, or (4) .tar file extension in a cartridge manifest file. | |
| Modificada | Baja (3.6) | 0.36% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp. | |
| Modificada | Baja (2.1) | 0.36% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent attackers to obtain sensitive information, as demonstrated by including log files or Bugzilla reports in support channels. | |
| Modificada | Media (5.8) | 1.5% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the PATH_INFO. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat OpenshiftRedhat Openshift Origin | 24/2/2013 | 16/6/2026 | node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO. |