Vulnerabilities
Vulnerable Software
Redhat:  >> Openshift  >> 4.12  Security Vulnerabilities
A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged users to set the seccomp profile for pods they control to "unconfined." By default, the seccomp profile used in the restricted-v2 Security Context Constraint (SCC) is "runtime/default," allowing users to disable seccomp for pods they can create and modify.
CVSS Score
6.3
EPSS Score
0.001
Published
2023-01-26
A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the oauth-serving-cert ConfigMaps, and accessible to any authenticated OpenShift user or service-account. A malicious user could exploit this flaw by reading the oauth-serving-cert ConfigMap in the openshift-config-managed namespace, compromising any web traffic secured using that certificate.
CVSS Score
6.5
EPSS Score
0.006
Published
2022-09-01


Contact Us

Shodan ® - All rights reserved