CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

redhat

openshift

69 known vulnerabilities · sorted by CVSS score

CVE-2013-2060
CRITICAL9.8

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.

redhat / openshift
Network
Published Jan 28, 2020
Page 1 of 4
CVE-2014-0175
CRITICAL9.8

mcollective has a default password set at install

puppet / marionette_collective+4
Network
Published Dec 13, 2019
CVE-2014-0234
CRITICAL9.8

The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a password of "mooo" for a Mongo account, which allows remote attackers to hijack the broker by providing this password, related to the openshift.sh script in Openshift Extras before 20130920. NOTE: this may overlap CVE-2013-4253 and CVE-2013-4281.

redhat / openshift
Network
Published Feb 12, 2020
CVE-2013-4561
CRITICAL9.1

In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

redhat / openshift
Network
Published Jun 30, 2022
CVE-2014-0163
HIGH8.8

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

redhat / openshift+1
Network
Published Dec 11, 2019
CVE-2018-1102
HIGH8.8

A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

redhat / openshift+9
Network
Published Apr 30, 2018
CVE-2019-5736
HIGH8.6

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image, or (2) an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe.

docker / docker+42
Local
Published Feb 11, 2019
CVE-2013-2103
HIGH8.1

OpenShift cartridge allows remote URL retrieval

redhat / openshift
Network
Published Dec 3, 2019
CVE-2022-3262
HIGH8.1

A flaw was found in Openshift. A pod with a DNSPolicy of "ClusterFirst" may incorrectly resolve the hostname based on a service provided. This flaw allows an attacker to supply an incorrect name with the DNS search policy, affecting confidentiality and availability.

redhat / openshift
Network
Published Dec 8, 2022
CVE-2021-4125
HIGH8.1

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift 4.8, 4.7 and 4.6.

redhat / openshift+2
Network
Published Aug 24, 2022
CVE-2024-1485
HIGH8.0

A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.

devfile / registry-support+2
Network
Published Feb 14, 2024
CVE-2014-0023
HIGH7.8

OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution

redhat / openshift
Local
Published Nov 15, 2019
CVE-2019-19349
HIGH7.8

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

redhat / openshift
Local
Published Mar 24, 2021
CVE-2013-4364
HIGH7.8

(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.

redhat / openshift+1
Local
Published Jan 8, 2018
CVE-2018-10875
HIGH7.8

A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

redhat / ansible_engine+18
Local
Published Jul 13, 2018
CVE-2019-19350
HIGH7.8

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to modify /etc/passwd and escalate their privileges.

redhat / openshift+1
Local
Published Mar 24, 2021
CVE-2021-4047
HIGH7.5

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.

redhat / openshift
Network
Published Apr 11, 2022
CVE-2024-12085
HIGH7.5

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

samba / rsync+62
Network
Published Jan 14, 2025
CVE-2013-4253
HIGH7.5

The deployment script in the unsupported "OpenShift Extras" set of add-on scripts, in Red Hat Openshift 1, installs a default public key in the root user's authorized_keys file.

redhat / openshift
Network
Published Oct 19, 2022
CVE-2012-6135
HIGH7.5

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

phusion / passenger+2
Network
Published Nov 19, 2019