atomic-openshift-hypershift vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the atomic-openshift-hypershift package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Improper Validation of Integrity Check Value

*
  • L
Information Exposure

*
  • H
Resource Exhaustion

*
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Truncation of Security-relevant Information

*
  • H
Resource Exhaustion

*
  • L
Incorrect Authorization

*
  • M
Cross-site Scripting (XSS)

*
  • M
Resource Exhaustion

*
  • M
CVE-2023-2727

*
  • M
CVE-2023-2728

*
  • M
Incorrect Default Permissions

*
  • M
Authentication Bypass by Primary Weakness

*
  • L
Information Exposure

<0:3.10.14-1.git.0.ba8ae6d.el7
  • M
Improper Input Validation

<0:3.11.248-1.git.0.92ee8ac.el7
  • M
Insufficiently Protected Credentials

*
  • H
Arbitrary Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Arbitrary Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Cleartext Storage of Sensitive Information

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Placement of User into Incorrect Group

*
  • C
Authentication Bypass by Primary Weakness

<0:3.11.43-1.git.0.647ac05.el7
  • C
Authentication Bypass by Primary Weakness

<0:3.10.72-1.git.0.3cb2fdc.el7
  • M
Improper Authentication

<0:3.11.153-1.git.0.aaf3f71.el7
  • M
Improper Authentication

<0:3.10.175-1.git.0.f9f0e81.el7
  • H
Cross-site Scripting (XSS)

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Cross-site Scripting (XSS)

*
  • M
Cross-site Scripting (XSS)

<0:3.11.188-1.git.0.db0eaa8.el7
  • C
Cross-site Scripting (XSS)

<0:3.11.43-1.git.0.647ac05.el7
  • M
Improper Access Control

*
  • L
Incorrect Authorization

*
  • M
Improper Input Validation

*
  • M
Information Exposure

<0:3.11.374-1.git.0.ebd3ee9.el7
  • M
Improper Output Neutralization for Logs

*
  • M
Open Redirect

*
  • M
Link Following

<0:3.11.117-1.git.0.14e54a3.el7
  • M
Link Following

<0:3.10.149-1.git.0.05de590.el7
  • M
Cross-site Request Forgery (CSRF)

<0:3.11.129-1.git.0.bd4f2d5.el7
  • M
Cross-site Request Forgery (CSRF)

*
  • H
Information Exposure

<0:3.11.51-1.git.0.1560686.el7
  • H
Session Fixation

<0:3.11.51-1.git.0.1560686.el7
  • H
Resource Exhaustion

<0:3.11.51-1.git.0.1560686.el7
  • H
Information Exposure

<0:3.11.51-1.git.0.1560686.el7
  • H
Static Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Link Following

<0:3.10.127-1.git.0.dab74c6.el7
  • M
Link Following

<0:3.11.98-1.git.0.0cbaff3.el7
  • H
Static Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Improper Authentication

<0:3.11.51-1.git.0.1560686.el7
  • H
Out-of-bounds Write

<0:3.10.66-1.git.0.91d1e89.el7
  • H
Out-of-bounds Write

<0:3.11.16-1.git.0.b48b8f8.el7
  • H
Static Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Session Fixation

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Session Fixation

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Improper Input Validation

<0:3.10.181-1.git.0.3ab4b3d.el7
  • M
Improper Input Validation

<0:3.11.129-1.git.0.bd4f2d5.el7
  • H
Static Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Improper Input Validation

<0:3.11.51-1.git.0.1560686.el7
  • M
Open Redirect

<0:3.11.346-1.git.0.ea10721.el7
  • H
Cross-site Scripting (XSS)

<0:3.11.51-1.git.0.1560686.el7
  • H
Directory Traversal

<0:3.11.51-1.git.0.1560686.el7
  • M
Authentication Bypass

*
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Directory Traversal

*
  • H
Authorization Bypass Through User-Controlled Key

*
  • M
Improper Validation of Array Index

*
  • M
Improper Certificate Validation

*
  • L
Improper Input Validation

*
  • H
Link Following

<0:3.11.524-1.git.0.2dffce7.el7
  • M
Improper Output Neutralization for Logs

*
  • L
Time-of-check Time-of-use (TOCTOU)

*
  • M
Improper Output Neutralization for Logs

<0:3.11.501-1.git.0.f8c4746.el7
  • L
Authentication Bypass

*
  • L
Authentication Bypass

*
  • H
Static Code Injection

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Resource Exhaustion

<0:3.11.232-1.git.0.a5bc32f.el7
  • H
Cross-site Scripting (XSS)

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Information Exposure

*
  • H
Cross-site Scripting (XSS)

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Insufficiently Protected Credentials

*
  • H
Cross-site Request Forgery (CSRF)

<0:3.11.82-1.git.0.08bc31b.el7
  • M
Information Exposure Through Log Files

*
  • M
Information Exposure Through Log Files

<0:3.11.157-1.git.0.dfe38da.el7
  • M
Authentication Bypass by Primary Weakness

<0:3.11.232-1.git.0.a5bc32f.el7
  • M
Authentication Bypass by Primary Weakness

*
  • H
Link Following

<0:3.11.154-1.git.0.7a097ad.el7
  • M
Link Following

*
  • L
Incorrect Permission Assignment for Critical Resource

*
  • L
Incorrect Permission Assignment for Critical Resource

<0:3.11.161-1.git.0.4ccbe25.el7
  • M
Improper Cleanup on Thrown Exception

<0:3.11.248-1.git.0.92ee8ac.el7
  • H
Resource Exhaustion

<0:3.11.154-1.git.0.7a097ad.el7
  • H
Resource Exhaustion

<0:3.10.181-1.git.0.3ab4b3d.el7
  • H
Directory Traversal

<0:3.10.181-1.git.0.3ab4b3d.el7
  • H
API Abuse

<0:3.11.170-1.git.0.00cac56.el7
  • H
Information Exposure

<0:3.11.170-1.git.0.00cac56.el7
  • H
Information Exposure

<0:3.11.170-1.git.0.00cac56.el7
  • H
Covert Timing Channel

<0:3.11.170-1.git.0.00cac56.el7
  • H
Covert Timing Channel

<0:3.11.170-1.git.0.00cac56.el7
  • H
Insufficient Control of Network Message Volume (Network Amplification)

<0:3.11.170-1.git.0.00cac56.el7
  • H
Authentication Bypass by Primary Weakness

<0:3.11.170-1.git.0.00cac56.el7
  • M
Resource Exhaustion

<0:3.11.542-1.git.0.f2fd300.el7
  • H
Improper Access Control

<0:3.10.170-1.git.0.8e592d6.el7
  • M
XML External Entity (XXE) Injection

<0:3.11.129-1.git.0.bd4f2d5.el7
  • M
Resource Exhaustion

<0:3.11.248-1.git.0.92ee8ac.el7
  • M
Man-in-the-Middle (MitM)

<0:3.11.248-1.git.0.92ee8ac.el7
  • M
Open Redirect

<0:3.11.346-1.git.0.ea10721.el7
  • M
Information Exposure

<0:3.11.232-1.git.0.a5bc32f.el7
  • M
Resource Exhaustion

*
  • M
Path Equivalence

*
  • L
Placement of User into Incorrect Group

*
  • M
Resource Exhaustion

*
  • M
Algorithmic Complexity

*
  • M
Improper Input Validation

*
  • M
Use of a Broken or Risky Cryptographic Algorithm

*
  • M
Resource Exhaustion

*
  • M
Information Exposure

*
  • H
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Use of Insufficiently Random Values

<0:3.11.374-1.git.0.ebd3ee9.el7
  • M
Use of Insufficiently Random Values

*
  • H
Out-of-bounds Read

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Resource Exhaustion

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Out-of-bounds Read

<0:3.11.82-1.git.0.08bc31b.el7
  • H
Out-of-bounds Read

<0:3.10.66-1.git.0.91d1e89.el7
  • L
Resource Exhaustion

*
  • M
Race Condition

*
  • L
Improper Input Validation

*
  • M
Resource Exhaustion

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • M
Improper Input Validation

<0:3.11.248-1.git.0.92ee8ac.el7
  • L
Directory Traversal

*
  • M
Incorrect Calculation

*
  • L
NULL Pointer Dereference

*
  • M
HTTP Response Splitting

<0:3.11.374-1.git.0.ebd3ee9.el7
  • L
Race Condition

*
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • H
Cross-site Scripting (XSS)

<0:3.11.170-1.git.0.00cac56.el7
  • M
Improper Certificate Validation

*
  • M
Improper Certificate Validation

*
  • M
Insufficiently Protected Credentials

<0:3.10.175-1.git.0.f9f0e81.el7
  • M
HTTP Request Smuggling

*
  • M
HTTP Request Smuggling

*
  • H
Resource Exhaustion

<0:3.10.170-1.git.0.8e592d6.el7
  • H
Resource Exhaustion

<0:3.11.153-1.git.0.aaf3f71.el7
  • H
Resource Exhaustion

<0:3.11.153-1.git.0.aaf3f71.el7
  • H
Resource Exhaustion

<0:3.10.170-1.git.0.8e592d6.el7
  • M
Improper Input Validation

*
  • M
Improper Input Validation

*
  • L
Improper Input Validation

*
  • L
Resource Exhaustion

*
  • L
Improper Input Validation

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
Improper Handling of Length Parameter Inconsistency

*
  • M
Use After Free

<0:3.11.248-1.git.0.92ee8ac.el7
  • C
Out-of-Bounds

<0:3.11.43-1.git.0.647ac05.el7