Vulnerability index

Browse CVEs

29 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
Satellite HIGH 8.8
CVE-2026-5136

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This …

Fix: 3.18.2 / 3.19.1+
Fix from $1,950 2026-07-01
Build Of Keycloak MEDIUM 6.5
CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role …

No fix yet
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-12388

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is …

Mitigation only
Fix from $1,600 2026-06-30
Build Of Keycloak HIGH 7.3
CVE-2026-9795

A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. An administrator with limited client management permissions can explo…

Mitigation only
Fix from $1,950 2026-05-28
Build Of Keycloak HIGH 7.2
CVE-2026-3121

A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to…

Mitigation only
Fix from $1,950 2026-03-26
Quay MEDIUM 6.5
CVE-2025-4374

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are gran…

Fix: after 3.14.0
Fix from $1,600 2025-05-06
Openshift Virtualization HIGH 7.0
CVE-2020-1742

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe…

Fix: 2.3.0+
Fix from $1,950 2021-06-07
Openshift HIGH 7.0
CVE-2020-35514

An insecure modification flaw in the /etc/kubernetes/kubeconfig file was found in OpenShift. This flaw allows an attacker with access to a running co…

Fix: 4.7.0+
Fix from $1,950 2021-06-02
Single Sign On HIGH 7.8
CVE-2020-10695

An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this …

Fix: 7.4.4+
Fix from $1,950 2021-05-26
Enterprise Linux MEDIUM 6.1
CVE-2021-20208

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credent…

Fix: 6.13+
Fix from $1,600 2021-04-19
Openshift Container Platform HIGH 7.8
CVE-2019-19354

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac…

Fix: 4.4.3+
Fix from $1,950 2021-03-24
Openshift Container Platform HIGH 7.0
CVE-2019-19352

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attac…

Mitigation only
Fix from $1,950 2021-03-24
Openshift Container Platform HIGH 7.0
CVE-2019-19353

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacke…

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19349

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat …

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19350

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an…

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.0
CVE-2019-19346

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.0
CVE-2019-19348

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.8
CVE-2019-19345

A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass…

Fix: 4.3+
Fix from $1,950 2020-03-20
Template Service Broker Operator HIGH 7.0
CVE-2020-1705

A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab…

Fix: 4.3.0+
Fix from $1,950 2020-03-19
Openshift HIGH 7.0
CVE-2019-19351

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…

Mitigation only
Fix from $1,950 2020-03-18
Openshift HIGH 7.0
CVE-2019-19355

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…

Mitigation only
Fix from $1,950 2020-03-18
Openshift Service Mesh HIGH 7.8
CVE-2020-1704

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…

Fix: 1.0.8+
Fix from $1,950 2020-02-17
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-7066

It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local u…

Fix: 7.1.0+
Fix from $1,950 2018-09-11
Ansible Tower HIGH 8.0
CVE-2016-7070

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trus…

Fix: 3.0.3+
Fix from $1,950 2018-09-11
Ansible Tower HIGH 7.2
CVE-2018-1101

Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. Syste…

Fix: 3.2.4+
Fix from $1,950 2018-05-02
Gluster Storage HIGH 8.1
CVE-2018-1088EPSS 6%

A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared …

Fix: after 3.13.2
Fix from $1,950 2018-04-18
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2012-4549

A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter…

Fix: after 6.0.0
Fix from $1,600 2013-01-05