Openshift Application Runtimes
Vendor:
First CVE: Jun 12, 2019 · Active for 7 years
33
Total CVEs
More Total CVEs than 97% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openshift Application Runtimes over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2019
7 years ago
Most Recent CVE
Sep 14, 2023
1,048 days ago
CVE Severity & Scoring
Openshift Application Runtimes33 CVEs
42%
42%
9%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (6.1%)
Network31 (93.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (87.9%)
High4 (12.1%)
Unknown0 (0.0%)
User Interaction
None30 (90.9%)
Unknown0 (0.0%)
Required3 (9.1%)
Privileges Required
Low13 (39.4%)
High2 (6.1%)
None18 (54.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2019-3888CRITICAL A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs t | Jun 12, 2019 | 9.8 | 33 | NO | NO |
CVE-2019-10212CRITICAL A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials fr | Oct 2, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-10174HIGH A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla | Nov 25, 2019 | 8.8 | 29 | NO | NO |
CVE-2020-1718HIGH A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application. | May 12, 2020 | 8.8 | 28 | NO | NO |
CVE-2019-14887CRITICAL A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf | Mar 16, 2020 | 9.1 | 28 | NO | NO |
CVE-2022-1319HIGH A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the | Aug 31, 2022 | 7.5 | 26 | NO | NO |
CVE-2023-1108HIGH A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. | Sep 14, 2023 | 7.5 | 25 | NO | NO |
CVE-2022-1259HIGH A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exis | Aug 31, 2022 | 7.5 | 25 | NO | NO |
CVE-2020-25644HIGH A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of se | Oct 6, 2020 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Openshift Application Runtimes
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 3 | 7.0 | 2.1% | 0 | 0 |