Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Build Of Keycloak MEDIUM 5.4
CVE-2026-16071

A flaw was found in the LDAP storage provider of Keycloak, which is used to federate user identities from external directories. The issue occurs when…

Fix: 26.4.14 / 26.6.5+
Fix from $1,600 2026-08-05
Openshift Container Platform HIGH 8.8
CVE-2026-54099

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a …

Fix: 4.22.1+
Fix from $1,950 2026-06-22
Build Of Keycloak MEDIUM 6.5
CVE-2025-7784

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative use…

Mitigation only
Fix from $1,600 2025-07-18
Openshift Container Platform HIGH 7.2
CVE-2023-5408

A privilege escalation flaw was found in the node restriction admission plugin of the kubernetes api server of OpenShift. A remote attacker who modif…

Patch available
Fix from $1,950 2023-11-02
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Enterprise Linux HIGH 7.8
CVE-2023-0664

A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows inst…

Fix: 8.0.0+
Fix from $1,950 2023-03-29
Openstack HIGH 8.8
CVE-2022-38065

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functio…

No fix yet
Fix from $1,950 2022-12-21
Ansible Automation Platform MEDIUM 6.5
CVE-2022-2568

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions…

No fix yet
Fix from $1,600 2022-08-18
Enterprise Linux MEDIUM 6.1
CVE-2021-20208

A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credent…

Fix: 6.13+
Fix from $1,600 2021-04-19
Openshift Container Platform HIGH 7.8
CVE-2019-19354

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac…

Fix: 4.4.3+
Fix from $1,950 2021-03-24
Openshift HIGH 7.0
CVE-2019-19346

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.0
CVE-2019-19348

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following…

Fix: 3.11.188-4 / 4.1.37+
Fix from $1,950 2020-04-02
Openshift HIGH 7.8
CVE-2019-19345

A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass…

Fix: 4.3+
Fix from $1,950 2020-03-20
Openshift HIGH 7.0
CVE-2019-19351

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…

Mitigation only
Fix from $1,950 2020-03-18
Openshift HIGH 7.0
CVE-2019-19355

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…

Mitigation only
Fix from $1,950 2020-03-18
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Jboss Application Server HIGH 7.8
CVE-2012-2312

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat …

Mitigation only
Fix from $1,950 2019-12-18
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Rkt HIGH 7.7
CVE-2019-10144

rkt through version 1.30.0 does not isolate processes in containers that are run with `rkt enter`. Processes run with `rkt enter` are given all capab…

Fix: after 1.30.0
Fix from $1,950 2019-06-03
Enterprise Linux MEDIUM 5.4
CVE-2018-16838

A flaw was found in sssd Group Policy Objects implementation. When the GPO is not readable by SSSD due to a too strict permission settings on the ser…

Mitigation only
Fix from $1,600 2019-03-25
Satellite HIGH 8.8
CVE-2017-2672

A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…

Fix: 1.15+
Fix from $1,950 2018-06-21
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7803

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforc…

Fix: 52.3.0 / 55.0+
Fix from $1,950 2018-06-11
Satellite MEDIUM 6.5
CVE-2017-10690

In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not classified to retrieve from.…

Fix: 5.3.4 / 2017.3.4+
Fix from $1,600 2018-02-09
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-0192

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…

Fix: 5.0.16.10 / 6.1.8.4+
Fix from $2,300 2015-07-02
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0643 KEVEPSS 11%

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x be…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27