Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 6.4 CVE-2025-57853 A container privilege escalation flaw was found in certain Web Terminal images. This issue stems from the /etc/passwd file being created with group-w… Web Terminal Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57854 A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being c… Openshift Update Service Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-58713 A container privilege escalation flaw was found in certain Red Hat Process Automation Manager images. This issue stems from the /etc/passwd file bein… Process Automation Manager Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.7 CVE-2025-57851 A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file bein… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-57847 A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being crea… Ansible Automation Platform after 2.6 Fix from $1,6002026-04-08 MEDIUM 6.4 CVE-2025-8766 A container privilege escalation flaw was found in certain Multi-Cloud Object Gateway Core images. This issue stems from the /etc/passwd file being c… Openshift Data Foundation Mitigation only Fix from $1,6002026-03-13 MEDIUM 6.4 CVE-2025-57849 A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable … Fuse Mitigation only Fix from $1,6002026-03-13 HIGH 7.3 CVE-2024-1488 A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runti… Codeready Linux Builder Patch available Fix from $1,9502024-02-15 MEDIUM 5.5 CVE-2024-23301 Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to syst… Enterprise Linux after 2.7 Fix from $1,6002024-01-12 MEDIUM 5.5 CVE-2023-4065 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 CRITICAL 9.8 CVE-2022-4039 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This … Single Sign On Mitigation only Fix from $2,3002023-09-22 MEDIUM 5.5 CVE-2022-3146 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3101 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2013-4281 In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users… Openshift Patch available Fix from $1,6002022-10-19 MEDIUM 5.5 CVE-2021-3917 A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw … Coreos Installer 0.10.0+ Fix from $1,6002022-08-23 MEDIUM 6.6 CVE-2021-3701 A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all… Ansible Runner Patch available Fix from $1,6002022-08-23 HIGH 8.8 CVE-2022-1833 A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th… Amq Broker Mitigation only Fix from $1,9502022-06-21 HIGH 7.5 CVE-2022-27649 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker E… Developer Tools Patch available Fix from $1,9502022-04-04 MEDIUM 6.3 CVE-2021-3948 An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces handling an attacker may be ab… Migration Toolkit 1.5.2 / 1.6.3+ Fix from $1,6002022-02-18 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 MEDIUM 5.5 CVE-2012-6136 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. Tuned Mitigation only Fix from $1,6002019-11-20 MEDIUM 5.0 CVE-2018-14650 It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada… Enterprise Linux Desktop Patch available Fix from $1,6002018-09-27 HIGH 7.8 CVE-2017-15131 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting… Enterprise Linux 0.15.5+ Fix from $1,9502018-01-09