Show filters
532 Total Results
Displaying 151-160 of 532
Sort by:
Attacker Value
Unknown
CVE-2017-7517
Disclosure Date: October 17, 2022 (last updated February 24, 2025)
An input validation vulnerability exists in Openshift Enterprise due to a 1:1 mapping of tenants in Hawkular Metrics and projects/namespaces in OpenShift. If a user creates a project called "MyProject", and then later deletes it another user can then create a project called "MyProject" and access the metrics stored from the original "MyProject" instance.
0
Attacker Value
Unknown
CVE-2022-2990
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
0
Attacker Value
Unknown
CVE-2022-2989
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.
0
Attacker Value
Unknown
CVE-2022-2403
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-config-managed namespace, compromising any web traffic secured using that certificate.
0
Attacker Value
Unknown
CVE-2022-1677
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname, or all hostnames in the cluster, and direct traffic to an arbitrary application within the cluster, including one under attacker control.
0
Attacker Value
Unknown
CVE-2022-1632
Disclosure Date: September 01, 2022 (last updated February 24, 2025)
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
0
Attacker Value
Unknown
CVE-2022-2132
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
0
Attacker Value
Unknown
CVE-2022-1319
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
0
Attacker Value
Unknown
CVE-2022-1259
Disclosure Date: August 31, 2022 (last updated February 24, 2025)
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
0
Attacker Value
Unknown
CVE-2022-0718
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
0