Loading HuntDB...

Red Hat OpenShift Container Platform 4.15

61 Versions 19 CVEs

Versions

415.92.202407301159-0

OTHER 1 CVE

v4.15.0-202409161436.p0.g4121cfc.assembly.stream.el9

OTHER 1 CVE

0:1.28.4-8.rhaos4.15.git24f50b9.el9

OTHER 1 CVE

v4.15.0-202409120135.p0.g8de6f94.assembly.stream.el9

OTHER 1 CVE

0:2.16.2-2.1.rhaos4.15.el9

OTHER 1 CVE

v4.15.0-202409180305.p0.g1da79fe.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202411060036.p0.gd8360d4.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-30.rhaos4.15.el9

OTHER 1 CVE

v4.15.0-202409130735.p0.gc03231f.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409111636.p0.gd80fe46.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202404161612.p0.g00d04f5.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409111636.p0.gf0c44f6.assembly.stream.el9

OTHER 1 CVE

2:1.11.2-21.2.rhaos4.15.el9

OTHER 1 CVE

415.92.202407191425-0

OTHER 1 CVE

0:1.28.11-5.rhaos4.15.git35a2431.el9

OTHER 2 CVEs

v4.15.0-202409161234.p0.g4e8d689.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409131635.p0.gb7c1d6a.assembly.stream.el9

OTHER 1 CVE

415.92.202407091355-0

OTHER 1 CVE

v4.15.0-202406200537.p0.g14489f7.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409172305.p0.g5af0be8.assembly.stream.el9

OTHER 1 CVE

1:1.4.0-1.2.rhaos4.15.el8

OTHER 1 CVE

v4.15.0-202409161836.p0.g092d15b.assembly.stream.el9

OTHER 1 CVE

4:1.1.12-1.1.rhaos4.15.el8

OTHER 1 CVE

3:4.4.1-21.1.rhaos4.15.el8

OTHER 1 CVE

0:4.15.0-202403211240.p0.g62c4d45.assembly.stream.el8

OTHER 1 CVE

0:0.20.0-1.1.rhaos4.15.el8

OTHER 1 CVE

v4.15.0-202409130536.p0.g1d6a7ed.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202410230304.p0.g366295f.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409180705.p0.g95ee44e.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409171307.p0.g160e7ca.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409161436.p0.g1f44c02.assembly.stream.el9

OTHER 1 CVE

415.92.202409162258-0

OTHER 2 CVEs

v4.15.0-202409171307.p0.ged4651a.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202410230304.p0.gfde2b2e.assembly.stream.el8

OTHER 1 CVE

3:4.4.1-23.2.rhaos4.15.el8

OTHER 1 CVE

v4.15.0-202409120135.p0.gf7f5eed.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409120135.p0.g71a6f28.assembly.stream.el9

OTHER 1 CVE

0:1.28.6-2.rhaos4.15.git77bbb1c.el9

OTHER 1 CVE

v4.15.0-202409120135.p0.g8425d88.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409120135.p0.g3ab953d.assembly.stream.el9

OTHER 1 CVE

0:1.28.7-2.rhaos4.15.git111aec5.el9

OTHER 1 CVE

v4.15.0-202409171307.p0.g5d529dd.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202406060836.p0.gf577b35.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409172305.p0.g17536c8.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409131835.p1.gbe9d673.assembly.stream.el9

OTHER 1 CVE

3:4.4.1-32.rhaos4.15.el8

OTHER 1 CVE

0:4.15.6-202403280951.p0.g94b1c2a.assembly.4.15.6.el9

OTHER 1 CVE

415.92.202411050056-0

OTHER 1 CVE

v4.15.0-202409131835.p0.gadccbd5.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202403220332.p0.gd3bdbce.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202407230407.p0.gf3f8de5.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409111636.p0.g9ea52de.assembly.stream.el9

OTHER 1 CVE

0:4.15.0-202403211549.p0.g2e3cca1.assembly.stream.el8

OTHER 1 CVE

0:1.28.0-3.1.el9

OTHER 1 CVE

2:1.11.3-4.rhaos4.15.el8

OTHER 1 CVE

1:1.29.1-20.3.rhaos4.15.el8

OTHER 1 CVE

v4.15.0-202409180905.p0.gf6f61ca.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409101936.p1.ge7749a3.assembly.stream.el8

OTHER 1 CVE

v4.15.0-202409131635.p0.gb73e37f.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202407230407.p0.g1326282.assembly.stream.el9

OTHER 1 CVE

v4.15.0-202409180105.p0.g1fdd5b0.assembly.stream.el9

OTHER 1 CVE

Recent CVEs

CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

UNKNOWN Oct 15, 2024

CVE-2024-9675

A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by the user running Buildah.

UNKNOWN Oct 09, 2024

CVE-2024-9341

A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw allows an attacker to exploit symbolic links and trick the system into mounting sensitive host directories inside a container. This issue also allows attackers to access critical host files, bypassing the intended isolation between containers and the host system.

UNKNOWN Oct 01, 2024

CVE-2024-45496

A flaw was found in OpenShift. This issue occurs due to the misuse of elevated privileges in the OpenShift Container Platform's build process. During the build initialization step, the git-clone container is run with a privileged security context, allowing unrestricted access to the node. An attacker with developer-level access can provide a crafted .gitconfig file containing commands executed during the cloning process, leading to arbitrary command execution on the worker node. An attacker running code in a privileged container could escalate their permissions on the node running the container.

UNKNOWN Sep 16, 2024

CVE-2024-7387

A flaw was found in openshift/builder. This vulnerability allows command injection via path traversal, where a malicious user can execute arbitrary commands on the OpenShift node running the builder container. When using the “Docker” strategy, executable files inside the privileged build container can be overridden using the `spec.source.secrets.secret.destinationDir` attribute of the `BuildConfig` definition. An attacker running code in a privileged container could escalate their permissions on the node running the container.

UNKNOWN Sep 16, 2024

CVE-2024-6508

An insufficient entropy vulnerability was found in the Openshift Console. In the authorization code type and implicit grant type, the OAuth2 protocol is vulnerable to a Cross-Site Request Forgery (CSRF) attack if the state parameter is used inefficiently. This flaw allows logging into the victim’s current application account using a third-party account without any restrictions.

UNKNOWN Aug 21, 2024

CVE-2024-7409

A flaw was found in the QEMU NBD Server. This vulnerability allows a denial of service (DoS) attack via improper synchronization during socket closure when a client keeps a socket open as the server is taken offline.

UNKNOWN Aug 05, 2024

CVE-2024-3727

A flaw was found in the github.com/containers/image library. This flaw allows attackers to trigger unexpected authenticated registry accesses on behalf of a victim user, causing resource exhaustion, local path traversal, and other attacks.

UNKNOWN May 09, 2024