openshift-clients vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the openshift-clients package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2025-68121

*
  • M
Improper Validation of Integrity Check Value

*
  • M
Directory Traversal

*
  • M
Resource Exhaustion

*
  • M
Missing Reference to Active Allocated Resource

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Server-Side Request Forgery (SSRF)

*
  • H
Excessive Platform Resource Consumption within a Loop

*
  • M
Improper Certificate Validation

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Reachable Assertion

*
  • M
Creation of Immutable Text Using String Concatenation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Improper Output Neutralization for Logs

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Information Exposure

*
  • M
Expected Behavior Violation

*
  • M
Expected Behavior Violation

*
  • H
Information Exposure

*
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Incorrect Authorization

*
  • L
Incorrect Authorization

*
  • L
Incorrect Authorization

*
  • L
Race Condition

*
  • L
Arbitrary Code Injection

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • L
Missing Authorization

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Authentication for Critical Function

*
  • M
Improper Certificate Validation

*
  • M
Insecure Default Variable Initialization

*
  • M
Insufficiently Protected Credentials

*
  • L
Improper Access Control

*
  • M
OS Command Injection

*
  • C
Authentication Bypass by Primary Weakness

*
  • H
Out-of-bounds Write

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Placement of User into Incorrect Group

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Missing Release of Resource after Effective Lifetime

*
  • M
Incorrect Default Permissions

*
  • M
Cross-site Scripting (XSS)

*
  • M
Use After Free

*
  • L
NULL Pointer Dereference

*
  • H
Link Following

*
  • M
Resource Exhaustion

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • M
Buffer Access with Incorrect Length Value

*
  • M
Algorithmic Complexity

*
  • M
Improperly Controlled Sequential Memory Allocation

*
  • M
Use of a Broken or Risky Cryptographic Algorithm

*
  • M
Resource Exhaustion

*
  • M
Resource Exhaustion

*
  • M
Unchecked Return Value

*
  • M
OS Command Injection

*
  • M
CVE-2025-4673

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Verification of Cryptographic Signature

*
  • M
Information Exposure

*
  • M
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Handling of Exceptional Conditions

*
  • L
Insufficient Entropy

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Resource Exhaustion

*
  • M
Use of Uninitialized Variable

*
  • M
Improper Validation of Integrity Check Value

*
  • L
Incorrect Authorization

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • L
Improper Input Validation

*
  • H
Resource Exhaustion

*
  • M
Incorrect Privilege Assignment

*
  • L
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Improper Authentication

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Preservation of Permissions

*
  • L
Inappropriate Encoding for Output Context

*
  • H
Authorization Bypass Through User-Controlled Key

*