openshift
Cloud & SaaScommercial
Top products
Latest CVEs
The 7 most recently published vulnerabilities affecting openshift.
- CVE-2021-4294OpenShift OSIN CheckClientSecret timing discrepancy2.6
- CVE-2015-3207In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.5.3
- CVE-2020-10752A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with ...7.5
- CVE-2013-0196A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain th...6.5
- CVE-2014-0163Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.8.8
- CVE-2014-0023OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution7.8
- CVE-2015-8945openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive p...5.1