Openshift Container Platform For Linuxone

Vendor:

First CVE: Feb 12, 2020 · Active for 6 years

17
Total CVEs
More Total CVEs than 93% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openshift Container Platform For Linuxone over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 12, 2020
6 years ago
Most Recent CVE
Nov 26, 2025
240 days ago

CVE Severity & Scoring

Openshift Container Platform For Linuxone17 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (11.8%)
Network15 (88.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (88.2%)
High2 (11.8%)
Unknown0 (0.0%)
User Interaction
None12 (70.6%)
Unknown0 (0.0%)
Required5 (29.4%)
Privileges Required
Low4 (23.5%)
High0 (0.0%)
None13 (76.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a ver
Nov 26, 20257.730NONO
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http:/
Sep 19, 20246.127NOYES
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection w
Feb 19, 20247.527NONO
The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or pot
Feb 12, 20207.527NONO
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory
Jun 12, 20257.526NONO
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Sep 25, 20237.824NONO
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use
Sep 22, 20239.824NONO
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Sep 14, 20237.524NONO
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validat
Apr 17, 20248.123NONO
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent req
Dec 21, 20238.123NONO

Exploit Exposure

Signals from CVEs in this product scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.9% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (17 CVEs).

Media Mentions

Signals from CVEs in this product scope (17 CVEs).

Top CNAs Publishing CVEs For Openshift Container Platform For Linuxone

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.997.51.6%01
4.217.55.1%00
4.1917.70.3%00
4.1827.60.7%00
4.1727.60.7%00
4.1637.20.9%00
4.1536.81.0%00
4.1436.81.0%00
4.1336.81.0%00
4.1257.50.6%00
4.1127.70.4%00
4.10107.51.5%01
4.117.55.1%00