Vulnerabilities > Openshift

DATE CVE VULNERABILITY TITLE RISK
2022-07-07 CVE-2015-3207 Missing Encryption of Sensitive Data vulnerability in Openshift Origin 3.0.0
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
network
low complexity
openshift CWE-311
5.3
2016-08-05 CVE-2015-8945 Credentials Management vulnerability in Openshift Origin
openshift-node in OpenShift Origin 1.1.6 and earlier improperly stores router credentials as envvars in the pod when the --credentials option is used, which allows local users to obtain sensitive private key information by reading the systemd journal.
local
high complexity
openshift CWE-255
5.1