Openshift Container Platform

Vendor:

First CVE: Nov 25, 2015 · Active for 10 years

314
Total CVEs
More Total CVEs than 100% of tracked products
31.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Openshift Container Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 25, 2015
10 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

CVE Severity & Scoring

Openshift Container Platform314 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local85 (27.1%)
Network224 (71.3%)
Unknown0 (0.0%)
Physical1 (0.3%)
Adjacent Network4 (1.3%)
Attack Complexity
Low250 (79.6%)
High64 (20.4%)
Unknown0 (0.0%)
User Interaction
None244 (77.7%)
Unknown0 (0.0%)
Required70 (22.3%)
Privileges Required
Low129 (41.1%)
High18 (5.7%)
None167 (53.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (314 CVEs).

314 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques
Mar 25, 201910.098YESYES
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/Meta
Dec 10, 20189.898YESYES
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo
Mar 8, 20199.996YESYES
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr
Mar 8, 20199.996YESYES
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by
Apr 8, 20197.893YESYES
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows
Jan 22, 20198.893NOYES
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a proble
Nov 25, 20159.890NOYES
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES

Exploit Exposure

Signals from CVEs in this product scope (314 CVEs).

CISA KEV
8 CVEs
2.5% of CVEs· 96th percentile
Metasploit
9 CVEs
2.9% of CVEs· 96th percentile
Nuclei
10 CVEs
3.2% of CVEs· 97th percentile
ExploitDB
13 CVEs
4.1% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (314 CVEs).

Media Mentions

Signals from CVEs in this product scope (314 CVEs).

Top CNAs Publishing CVEs For Openshift Container Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.9126.30.8%00
4.856.816.7%00
4.756.820.9%11
4.6.114.30.7%00
4.6156.46.0%00
4.5.1616.50.9%00
4.556.81.6%00
4.456.81.6%00
4.357.42.6%00
4.2166.87.0%00
4.1917.70.3%00
4.1827.60.7%00
4.1767.02.1%00
4.1677.01.9%00
4.1577.02.0%00
4.1497.01.8%00
4.13107.11.8%00
4.12257.01.5%01
4.11187.01.4%01
4.10146.71.1%00