Openshift Application Runtimes

Vendor:

First CVE: Jun 12, 2019 · Active for 7 years

33
Total CVEs
More Total CVEs than 97% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openshift Application Runtimes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 12, 2019
7 years ago
Most Recent CVE
Sep 14, 2023
1,048 days ago

CVE Severity & Scoring

Openshift Application Runtimes33 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local2 (6.1%)
Network31 (93.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (87.9%)
High4 (12.1%)
Unknown0 (0.0%)
User Interaction
None30 (90.9%)
Unknown0 (0.0%)
Required3 (9.1%)
Privileges Required
Low13 (39.4%)
High2 (6.1%)
None18 (54.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName
Dec 14, 20217.570NONO
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs t
Jun 12, 20199.833NONO
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials fr
Oct 2, 20199.831NONO
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any cla
Nov 25, 20198.829NONO
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
May 12, 20208.828NONO
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traf
Mar 16, 20209.128NONO
A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the
Aug 31, 20227.526NONO
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Sep 14, 20237.525NONO
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exis
Aug 31, 20227.525NONO
A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of se
Oct 6, 20207.525NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Openshift Application Runtimes

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.037.02.1%00