Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Web Terminal MEDIUM 6.4
CVE-2025-57853

A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w…

Mitigation only
Fix from $1,600 2026-04-08
Openshift Update Service MEDIUM 6.4
CVE-2025-57854

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-04-08
Process Automation Manager MEDIUM 6.4
CVE-2025-58713

A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Advanced Cluster Management For Kubernetes MEDIUM 6.7
CVE-2025-57851

A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein…

Mitigation only
Fix from $1,600 2026-04-08
Ansible Automation Platform MEDIUM 6.4
CVE-2025-57847

A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea…

Fix: after 2.6
Fix from $1,600 2026-04-08
Openshift Data Foundation MEDIUM 6.4
CVE-2025-8766

A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c…

Mitigation only
Fix from $1,600 2026-03-13
Fuse MEDIUM 6.4
CVE-2025-57849

A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable …

Mitigation only
Fix from $1,600 2026-03-13
Codeready Linux Builder HIGH 7.3
CVE-2024-1488

A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti…

Patch available
Fix from $1,950 2024-02-15
Enterprise Linux MEDIUM 5.5
CVE-2024-23301

Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst…

Fix: after 2.7
Fix from $1,600 2024-01-12
Jboss A Mq MEDIUM 5.5
CVE-2023-4065

A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera…

Mitigation only
Fix from $1,600 2023-09-27
Single Sign On CRITICAL 9.8
CVE-2022-4039

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …

Mitigation only
Fix from $2,300 2023-09-22
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openshift MEDIUM 5.5
CVE-2013-4281

In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users…

Patch available
Fix from $1,600 2022-10-19
Coreos Installer MEDIUM 5.5
CVE-2021-3917

A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw …

Fix: 0.10.0+
Fix from $1,600 2022-08-23
Ansible Runner MEDIUM 6.6
CVE-2021-3701

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all…

Patch available
Fix from $1,600 2022-08-23
Amq Broker HIGH 8.8
CVE-2022-1833

A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th…

Mitigation only
Fix from $1,950 2022-06-21
Developer Tools HIGH 7.5
CVE-2022-27649

A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E…

Patch available
Fix from $1,950 2022-04-04
Migration Toolkit MEDIUM 6.3
CVE-2021-3948

An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab…

Fix: 1.5.2 / 1.6.3+
Fix from $1,600 2022-02-18
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Tuned MEDIUM 5.5
CVE-2012-6136

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

Mitigation only
Fix from $1,600 2019-11-20
Enterprise Linux Desktop MEDIUM 5.0
CVE-2018-14650

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada…

Patch available
Fix from $1,600 2018-09-27
Enterprise Linux HIGH 7.8
CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…

Fix: 0.15.5+
Fix from $1,950 2018-01-09