Openshift

Vendor:

First CVE: Dec 18, 2012 · Active for 13 years

181
Total CVEs
More Total CVEs than 99% of tracked products
12.1
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Openshift over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2012
13 years ago
Most Recent CVE
Apr 1, 2026
114 days ago

CVE Severity & Scoring

Openshift181 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local34 (18.8%)
Network98 (54.1%)
Unknown43 (23.8%)
Physical1 (0.6%)
Adjacent Network5 (2.8%)
Attack Complexity
Low116 (64.1%)
High22 (12.2%)
Unknown43 (23.8%)
User Interaction
None118 (65.2%)
Unknown43 (23.8%)
Required20 (11.0%)
Privileges Required
Low68 (37.6%)
High9 (5.0%)
None61 (33.7%)
Unknown43 (23.8%)

Top CVEs

Signals from CVEs in this product scope (181 CVEs).

181 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi
Feb 11, 20198.691NOYES
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, rel
Apr 7, 20168.888NOYES
Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fus
Nov 9, 20179.874NONO
The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.
Nov 25, 20157.570YESNO
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serializ
Jan 8, 20169.847NONO
Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS
Jul 3, 20169.834NONO
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.
Apr 7, 20169.834NONO
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart.
Jan 28, 20209.833NONO
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis
Jan 14, 20257.532NONO

Exploit Exposure

Signals from CVEs in this product scope (181 CVEs).

CISA KEV
2 CVEs
1.1% of CVEs· 96th percentile
Metasploit
2 CVEs
1.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (181 CVEs).

Media Mentions

Signals from CVEs in this product scope (181 CVEs).

Top CNAs Publishing CVEs For Openshift

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.017.58.7%00
4.947.00.6%00
4.7.017.00.2%00
4.235.80.8%00
4.1216.30.7%00
4.1125.80.5%00
4.115.40.6%00
4.0107.20.5%00
3.936.51.2%00
3.827.11.5%00
3.757.120.5%01
3.647.025.5%01
3.537.633.9%01
3.446.825.7%01
3.3.1.1114.31.3%00
3.347.51.4%00
3.2.1.2314.31.3%00
3.2186.32.1%00
3.1166.70.4%00
3.1026.51.8%00