Vulnerability index

Browse CVEs

128 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-16108

A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are…

No fix yet
Fix from $1,600 2026-07-17
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9908

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated use…

Fix: 2.6+
Fix from $1,600 2026-02-27
Ansible Automation Platform MEDIUM 6.7
CVE-2025-9907

A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensi…

Fix: 2.6+
Fix from $1,600 2026-02-27
Openshift Container Platform MEDIUM 5.3
CVE-2024-50312

A vulnerability was found in GraphQL due to improper access controls on the GraphQL introspection query. This flaw allows unauthorized users to retri…

Patch available
Fix from $1,600 2024-10-22
Openstack Platform MEDIUM 5.0
CVE-2024-7319

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon …

Mitigation only
Fix from $1,600 2024-08-02
Satellite MEDIUM 6.2
CVE-2024-3716

A flaw was found in foreman-installer when puppet-candlepin is invoked cpdb with the --password parameter. This issue leaks the password in the proce…

Mitigation only
Fix from $1,600 2024-06-05
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2024-1102

A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for…

Fix: 2.2.1+
Fix from $1,600 2024-04-25
Build Of Quarkus MEDIUM 5.3
CVE-2023-6393

A flaw was found in the Quarkus Cache Runtime. When request processing utilizes a Uni cached using @CacheResult and the cached Uni reuses the initial…

Mitigation only
Fix from $1,600 2023-12-06
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2023-4061

A flaw was found in wildfly-core. A management user could use the resolve-expression in the HAL Interface to read possible sensitive information from…

Fix: 15.0.30+
Fix from $1,600 2023-11-08
Openshift Data Science HIGH 7.5
CVE-2023-3361

A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads…

Fix: 1.28.1+
Fix from $1,950 2023-10-04
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24
Directory Server MEDIUM 5.5
CVE-2023-1055

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib…

Mitigation only
Fix from $1,600 2023-02-27
Enterprise Linux Server MEDIUM 5.3
CVE-2022-2739

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,600 2022-09-01
Enterprise Linux MEDIUM 5.5
CVE-2022-0851

There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription…

No fix yet
Fix from $1,600 2022-08-29
Satellite HIGH 8.8
CVE-2021-3590

A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…

Mitigation only
Fix from $1,950 2022-08-22
Business Central HIGH 7.5
CVE-2019-14839

It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercep…

Fix: after 7.48.0
Fix from $1,950 2022-04-01
Enterprise Linux MEDIUM 5.5
CVE-2021-3602

An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Doc…

Fix: 1.16.8 / 1.17.2+
Fix from $1,600 2022-03-03
Satellite MEDIUM 6.5
CVE-2020-14371

A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on t…

Mitigation only
Fix from $1,600 2021-06-02
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Ansible Engine HIGH 7.5
CVE-2021-20228

A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using th…

Patch available
Fix from $1,950 2021-04-29
Satellite MEDIUM 6.3
CVE-2021-3413

A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az…

Fix: 2.2.0+
Fix from $1,600 2021-04-08
389 Directory Server MEDIUM 5.3
CVE-2020-35518

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un…

Fix: 1.4.3.19 / 1.4.4.13+
Fix from $1,600 2021-03-26
Satellite MEDIUM 5.3
CVE-2021-20256

A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm…

Mitigation only
Fix from $1,600 2021-02-23
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Ansible Engine MEDIUM 5.0
CVE-2020-1746

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well a…

Fix: 2.7.17 / 2.8.11+
Fix from $1,600 2020-05-12
Keycloak MEDIUM 5.5
CVE-2020-1698

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…

Fix: 9.0.0+
Fix from $1,600 2020-05-11
Undertow HIGH 8.1
CVE-2020-1757

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.…

Fix: 2.1.0+
Fix from $1,950 2020-04-21
Ceph Storage HIGH 7.5
CVE-2020-1699

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i…

Mitigation only
Fix from $1,950 2020-04-21
Enterprise Linux MEDIUM 6.8
CVE-2020-2732

A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under s…

Patch available
Fix from $1,600 2020-04-08