Remote Code Execution Vulnerability in Red Hat OpenShift Container Platform
A critical remote code execution vulnerability, tracked as CVE-2024-8979, allows unauthenticated remote attackers to execute arbitrary code within the Red Hat OpenShift Container Platform environment.
CVE search metadata
CVE search record: CVE-2024-8979. Severity: high. CVSS: 8.0. EPSS: 0.49%. KEV: no. Product: OpenShift Container Platform. Brief: Remote Code Execution Vulnerability in Red Hat OpenShift Container Platform. Brief link: https://feed.craftedsignal.io/briefs/2026-08-redhat-openshift-rce/
Red Hat has identified a critical vulnerability within the OpenShift Container Platform that enables a remote, unauthenticated attacker to achieve arbitrary code execution. This vulnerability, identified as CVE-2024-8979, represents a significant risk to the integrity and security of containerized environments managed by the platform. Attackers can leverage this flaw to bypass authentication mechanisms and execute commands directly on the platform infrastructure. Given the critical nature of the flaw and the potential for full system compromise, organizations running Red Hat OpenShift should immediately review vendor security advisories and apply available patches or configuration mitigations to secure their container orchestration clusters.
Impact
Successful exploitation of this vulnerability results in full remote code execution on the affected Red Hat OpenShift nodes. This grants an attacker the ability to manipulate container workloads, access sensitive data residing in the cluster, and potentially move laterally within the organization's network. The scope of impact encompasses all organizations utilizing vulnerable versions of the OpenShift Container Platform.
Recommendation
- Identify all Red Hat OpenShift Container Platform installations within the environment that are subject to the advisory for CVE-2024-8979.
- Apply security patches provided by Red Hat to remediate the vulnerability across all cluster nodes immediately.
- Monitor cluster logs and audit trails for unauthorized execution patterns or anomalous administrative commands that could indicate exploitation attempts.
Immediate actions
Patch OpenShift Container Platform instances according to vendor guidance for CVE-2024-8979.
Mitigations
Patch affected software
CVE-2024-8979