Where
AND
-Infinity
0
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

1 / 2
Source: NVD
First published (updated )
Severity
7.6
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file into the build pod. This file contains sensitive credentials necessary for pulling images from private repositories. The mount is not read-only, which allows the attacker to overwrite it. By modifying the config.json file, the attacker can cause a denial of service by preventing the node from pulling new images and potentially exfiltrating sensitive secrets. This flaw impacts the availability of services dependent on image pulls and exposes sensitive information to unauthorized parties.

1 / 2
Source: NVD
First published (updated )
Severity
7
Path Traversal

Important: OpenShift Container Platform 4.21.29 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.14.71 bug fix and security update

First published (updated )
Severity
7

OpenShift Container Platform 4.19.42 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.18.52 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.20.33 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.15.67 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.14.70 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

A flaw was found in the OpenShift Container Platform where the initialization container for builds (git-clone) runs with elevated privileges. This misconfiguration allows an attacker with developer access to create a malicious .gitconfig file that executes arbitrary commands on a privileged build pod. As a result, the attacker can compromise the worker node hosting the build pod, potentially gaining access to all the workloads running on that node. The impact is critical, as it allows for the compromise of the node's identity and other nodes, depending on cluster configuration.

First published (updated )
Severity
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Cloud Credential Operator (CCO) Mint-mode CredentialsRequest manifests shipped with OpenShift Container Platform for AWS. The CredentialsRequest specifications for the Image Registry, Machine API, Ingress Operator, and EBS CSI Driver request IAM policies with Resource: "" for destructive actions (S3 CreateBucket/DeleteBucket/PutObject/DeleteObject, EC2 TerminateInstances/RunInstances, Route53 ChangeResourceRecordSets, EC2 DeleteVolume/DeleteSnapshot). This grants the provisioned operator IAM credentials access to any AWS resource in the account, not just resources owned by the cluster. An attacker who obtains these credentials (via pod compromise, RBAC escalation, or Secret read) can perform destructive operations against unrelated AWS resources in the same account, including deleting S3 buckets, terminating EC2 instances, modifying DNS records in unrelated hosted zones, and deleting EBS volumes belonging to other workloads or clusters.

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.20.30 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

RHTAS 1.3.6 - Red Hat Trusted Artifact Signer Release

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.12.93 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.12.93 security and extras update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.17.55 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

RHTAS 1.4.2 - Red Hat Trusted Artifact Signer Release

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.13.68 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.20.26 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.21.21 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.22.2 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

OpenShift Container Platform 4.19.33 bug fix and security update

1 / 2
Source: Red Hat

Remedy

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:<br><a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/" target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/</a> You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at <a href="https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags." target="_blank">https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.</a> The sha values for the release are as follows:<br>(For x86_64 architecture)<br> The image digest is sha256:f7c8010c24807273c8b9e77064d4a7089c8fcf6585749d864b55b98176ba745f<br>(For s390x architecture)<br> The image digest is sha256:093b7cfbad0f920f6f5668c9edfa120a5fd43ed24c71020464133dab18d4394a<br>(For ppc64le architecture)<br> The image digest is sha256:8121257742990c3b7d3b1dc4661f6029cf694a7f5f85d7497a466a019b029b20<br>(For aarch64 architecture)<br> The image digest is sha256:d73df62e9d3254daccf3fabc888e4081a67e39048191517292fdf0b60c19c7b5<br>All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at <a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli." target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.</a>
First published (updated )
Severity
7

Important: OpenShift Container Platform 4.12.91 bug fix and security update

First published (updated )
Severity
7
Buffer Overflow, Integer Overflow, Use After Free, Command Injection, OS Command Injection

Important: OpenShift Container Platform 4.14.65 bug fix and security update

Remedy

For OpenShift Container Platform 4.14 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:<br><a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/" target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html/release_notes/</a> You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at <a href="https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags." target="_blank">https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.</a> The sha values for the release are as follows:<br>(For x86_64 architecture)<br> The image digest is sha256:58619bd3685bebf42b1de421a21dd74d429a73d2842db8530468811dd8c762f6<br>(For s390x architecture)<br> The image digest is sha256:a42b5d59c2d8006a7531f21bf9494508a2223cfe0305c8323dd8d8805edd5bb6<br>(For ppc64le architecture)<br> The image digest is sha256:b3348021ca46196e46190a64246264ce6793628e3ed80b4957c0352c42014d01<br>(For aarch64 architecture)<br> The image digest is sha256:c40d6097277e7aacf96a3e883fb77cbd3d9cd42e698f98daaadf69204abaad4a<br>All OpenShift Container Platform 4.14 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at <a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli." target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.14/html-single/updating_clusters/index#updating-cluster-cli.</a>
First published (updated )
Severity
7

OpenShift allows a user to create his own images with the help of the build component. This component has three primary build strategies available (Docu - Understanding image builds):

Docker build Source-to-Image (S2I) build Custom build

As the builds are running in a privileged container, a vulnerability in this process allows an attacker to escalate their permissions on the cluster and host nodes.

The custom build is not safe, because they can execute any code within a privileged container and are disabled by default. The other two strategies are considered as safe and are enabled for all users that can create builds.

But there is a note about the docker strategy:

Grant docker build permissions with caution, because a vulnerability in the Dockerfile processing logic could result in a privileges being granted on the host node.

See: https://docs.openshift.com/container-platform/4.16/cicd/builds/securing-builds-by-strategy.html

The docker strategy / the image used during the build has a vulnerability, which allows an attacker to override files inside the privileged build container with the help of the spec.source.secrets.secret.destinationDir attribute of the BuildConfig definition. After overriding the binary, execution of this overriden file can be triggered with another secret and the malicious code is executed in the privileged container.

As stated above, running code in a privileged container allows an attacker to escalate their permissions on the cluster and host nodes. As an example the host filesystem of the worker node can be mounted and a new SSH key can be added to user core of the Red Hat Enterprise Linux CoreOS (RHCOS).

First published (updated )
Severity
7
Buffer Overflow, Use After Free, Command Injection, OS Command Injection

Important: OpenShift Container Platform 4.19.28 bug fix and security update

Remedy

For OpenShift Container Platform 4.19 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update:<br><a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/" target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html/release_notes/</a> You may download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests may be found at <a href="https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags." target="_blank">https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags.</a> The sha values for the release are as follows:<br>(For x86_64 architecture)<br> The image digest is sha256:b274766f7194a7dc825e335a54078790519c0dbe3431c029fd08dbba1c431855<br>(For s390x architecture)<br> The image digest is sha256:066bfcb590ef6f34106e63861d420a3fdcdebd734bb729668c8c6de59b84c632<br>(For ppc64le architecture)<br> The image digest is sha256:ff14e60b2b4760a6c2578e444b40f457fe2322f5211b1b838078b1fa6ea1b443<br>(For aarch64 architecture)<br> The image digest is sha256:52b1e8cf83dd1a854194212cc94bfe2719afb2e014f7b1a315250a9c7273a600<br>All OpenShift Container Platform 4.19 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at<br><a href="https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli." target="_blank">https://docs.redhat.com/en/documentation/openshift_container_platform/4.19/html-single/updating_clusters/index#updating-cluster-cli.</a>
First published (updated )
Severity
7.8
Path Traversal
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.

1 / 2
Source: NVD
First published (updated )
Severity
7.5
EPSS
0.10%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

First published (updated )
Severity
8.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that matches the name of a worker node.

1 / 2
Source: GitHub
First published (updated )
Severity
7.2
EPSS
0.51%
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A flaw was discovered in the node restriction admission plugin of the kubernetes api server of OpenShift. It could allow steering workloads from the control plane and etcd nodes onto a different worker node and gain higher credentials on the cluster.

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203