Openshift Origin
Vendor:
First CVE: Feb 24, 2013 · Active for 13 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openshift Origin over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2013
13 years ago
Most Recent CVE
Nov 21, 2019
2,437 days ago
CVE Severity & Scoring
Openshift Origin10 CVEs
30%
40%
30%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (20.0%)
Network2 (20.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None3 (30.0%)
Unknown6 (60.0%)
Required1 (10.0%)
Privileges Required
Low3 (30.0%)
High0 (0.0%)
None1 (10.0%)
Unknown6 (60.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-3496HIGH cartridge_repository.rb in OpenShift Origin and Enterprise 1.2.8 through 2.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a Source-Url ending | Jun 20, 2014 | 10.0 | 32 | NO | NO |
CVE-2016-2160HIGH Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root password in an sti builder imag | Jun 8, 2016 | 8.8 | 28 | NO | NO |
CVE-2012-5646HIGH node-util/www/html/restorer.php in the Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to execute arbitrary commands via a crafted uuid in the PATH_INFO. | Feb 24, 2013 | 7.5 | 22 | NO | NO |
CVE-2012-5647MEDIUM Open redirect vulnerability in node-util/www/html/restorer.php in Red Hat OpenShift Origin before 1.0.5-3 allows remote attackers to redirect users to arbitrary web sites and condu | Feb 24, 2013 | 5.8 | 18 | NO | NO |
CVE-2014-3592MEDIUM OpenShift Origin: Improperly validated team names could allow stored XSS attacks | Nov 13, 2019 | 6.1 | 17 | NO | NO |
CVE-2014-0084MEDIUM Ruby gem openshift-origin-node before 2014-02-14 does not contain a cronjob timeout which could result in a denial of service in cron.daily and cron.weekly. | Nov 21, 2019 | 5.5 | 16 | NO | NO |
HAproxy in Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allows local users to obtain the internal IP address of a pod by reading the "OPENSHIFT_[namespace]_SERVERID" cooki | Jun 8, 2016 | 3.3 | 16 | NO | NO |
The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a te | Feb 24, 2013 | 3.6 | 15 | NO | NO |
CVE-2015-5250MEDIUM The API server in OpenShift Origin 1.0.5 allows remote attackers to cause a denial of service (master process crash) via crafted JSON data. | Sep 8, 2015 | 4.0 | 14 | NO | NO |
rhc-chk.rb in Red Hat OpenShift Origin before 1.1, when -d (debug mode) is used, outputs the password and other sensitive information in cleartext, which allows context-dependent a | Feb 24, 2013 | 2.1 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Openshift Origin
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.1 | 1 | 10.0 | 5.1% | 0 | 0 |
| 2.1 | 1 | 10.0 | 5.1% | 0 | 0 |
| 1.2.8 | 1 | 10.0 | 5.1% | 0 | 0 |
| 1.0.5 | 3 | 3.2 | 0.9% | 0 | 0 |