Openshift
Vendor:
First CVE: Dec 18, 2012 · Active for 13 years
181
Total CVEs
More Total CVEs than 99% of tracked products
12.1
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 28% of tracked products
1.1%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Openshift over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 18, 2012
13 years ago
Most Recent CVE
Apr 1, 2026
114 days ago
CVE Severity & Scoring
Openshift181 CVEs
50%
35%
8%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local34 (18.8%)
Network98 (54.1%)
Unknown43 (23.8%)
Physical1 (0.6%)
Adjacent Network5 (2.8%)
Attack Complexity
Low116 (64.1%)
High22 (12.2%)
Unknown43 (23.8%)
User Interaction
None118 (65.2%)
Unknown43 (23.8%)
Required20 (11.0%)
Privileges Required
Low68 (37.6%)
High9 (5.0%)
None61 (33.7%)
Unknown43 (23.8%)
Top CVEs
Signals from CVEs in this product scope (181 CVEs).
181 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2019-5736HIGH runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveragi | Feb 11, 2019 | 8.6 | 91 | NO | YES |
CVE-2016-0792HIGH Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, rel | Apr 7, 2016 | 8.8 | 88 | NO | YES |
CVE-2015-7501CRITICAL Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fus | Nov 9, 2017 | 9.8 | 74 | NO | NO |
CVE-2015-5317HIGH The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request. | Nov 25, 2015 | 7.5 | 70 | YES | NO |
CVE-2015-5254CRITICAL Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serializ | Jan 8, 2016 | 9.8 | 47 | NO | NO |
CVE-2016-2074CRITICAL Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS | Jul 3, 2016 | 9.8 | 34 | NO | NO |
CVE-2016-0788CRITICAL The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener. | Apr 7, 2016 | 9.8 | 34 | NO | NO |
CVE-2013-2060CRITICAL The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart. | Jan 28, 2020 | 9.8 | 33 | NO | NO |
CVE-2024-12085HIGH A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparis | Jan 14, 2025 | 7.5 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (181 CVEs).
CISA KEV
2 CVEs
1.1% of CVEs· 96th percentile
Metasploit
2 CVEs
1.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
2.2% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (181 CVEs).
Media Mentions
Signals from CVEs in this product scope (181 CVEs).
Top CNAs Publishing CVEs For Openshift
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 7.5 | 8.7% | 0 | 0 |
| 4.9 | 4 | 7.0 | 0.6% | 0 | 0 |
| 4.7.0 | 1 | 7.0 | 0.2% | 0 | 0 |
| 4.2 | 3 | 5.8 | 0.8% | 0 | 0 |
| 4.12 | 1 | 6.3 | 0.7% | 0 | 0 |
| 4.11 | 2 | 5.8 | 0.5% | 0 | 0 |
| 4.1 | 1 | 5.4 | 0.6% | 0 | 0 |
| 4.0 | 10 | 7.2 | 0.5% | 0 | 0 |
| 3.9 | 3 | 6.5 | 1.2% | 0 | 0 |
| 3.8 | 2 | 7.1 | 1.5% | 0 | 0 |
| 3.7 | 5 | 7.1 | 20.5% | 0 | 1 |
| 3.6 | 4 | 7.0 | 25.5% | 0 | 1 |
| 3.5 | 3 | 7.6 | 33.9% | 0 | 1 |
| 3.4 | 4 | 6.8 | 25.7% | 0 | 1 |
| 3.3.1.11 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.3 | 4 | 7.5 | 1.4% | 0 | 0 |
| 3.2.1.23 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.2 | 18 | 6.3 | 2.1% | 0 | 0 |
| 3.11 | 6 | 6.7 | 0.4% | 0 | 0 |
| 3.10 | 2 | 6.5 | 1.8% | 0 | 0 |