Openshift Container Platform
Vendor:
First CVE: Nov 25, 2015 · Active for 10 years
314
Total CVEs
More Total CVEs than 100% of tracked products
31.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Openshift Container Platform over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 25, 2015
10 years ago
Most Recent CVE
Jun 29, 2026
25 days ago
CVE Severity & Scoring
Openshift Container Platform314 CVEs
39%
45%
13%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local85 (27.1%)
Network224 (71.3%)
Unknown0 (0.0%)
Physical1 (0.3%)
Adjacent Network4 (1.3%)
Attack Complexity
Low250 (79.6%)
High64 (20.4%)
Unknown0 (0.0%)
User Interaction
None244 (77.7%)
Unknown0 (0.0%)
Required70 (22.3%)
Privileges Required
Low129 (41.1%)
High18 (5.7%)
None167 (53.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (314 CVEs).
314 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2019-7609CRITICAL Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a reques | Mar 25, 2019 | 10.0 | 98 | YES | YES |
CVE-2018-1000861CRITICAL A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/Meta | Dec 10, 2018 | 9.8 | 98 | YES | YES |
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2019-1003030CRITICAL A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-1003029CRITICAL A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java, sr | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2019-0211HIGH In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by | Apr 8, 2019 | 7.8 | 93 | YES | YES |
CVE-2019-1003000HIGH A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows | Jan 22, 2019 | 8.8 | 93 | NO | YES |
CVE-2015-8103CRITICAL The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a proble | Nov 25, 2015 | 9.8 | 90 | NO | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (314 CVEs).
CISA KEV
8 CVEs
2.5% of CVEs· 96th percentile
Metasploit
9 CVEs
2.9% of CVEs· 96th percentile
Nuclei
10 CVEs
3.2% of CVEs· 97th percentile
ExploitDB
13 CVEs
4.1% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (314 CVEs).
Media Mentions
Signals from CVEs in this product scope (314 CVEs).
Top CNAs Publishing CVEs For Openshift Container Platform
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.9 | 12 | 6.3 | 0.8% | 0 | 0 |
| 4.8 | 5 | 6.8 | 16.7% | 0 | 0 |
| 4.7 | 5 | 6.8 | 20.9% | 1 | 1 |
| 4.6.1 | 1 | 4.3 | 0.7% | 0 | 0 |
| 4.6 | 15 | 6.4 | 6.0% | 0 | 0 |
| 4.5.16 | 1 | 6.5 | 0.9% | 0 | 0 |
| 4.5 | 5 | 6.8 | 1.6% | 0 | 0 |
| 4.4 | 5 | 6.8 | 1.6% | 0 | 0 |
| 4.3 | 5 | 7.4 | 2.6% | 0 | 0 |
| 4.2 | 16 | 6.8 | 7.0% | 0 | 0 |
| 4.19 | 1 | 7.7 | 0.3% | 0 | 0 |
| 4.18 | 2 | 7.6 | 0.7% | 0 | 0 |
| 4.17 | 6 | 7.0 | 2.1% | 0 | 0 |
| 4.16 | 7 | 7.0 | 1.9% | 0 | 0 |
| 4.15 | 7 | 7.0 | 2.0% | 0 | 0 |
| 4.14 | 9 | 7.0 | 1.8% | 0 | 0 |
| 4.13 | 10 | 7.1 | 1.8% | 0 | 0 |
| 4.12 | 25 | 7.0 | 1.5% | 0 | 1 |
| 4.11 | 18 | 7.0 | 1.4% | 0 | 1 |
| 4.10 | 14 | 6.7 | 1.1% | 0 | 0 |