Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-18207

A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of …

No fix yet
Fix from $1,600 2026-07-29
Apicast HIGH 7.5
CVE-2023-0456

A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul…

Fix: 2.12.2 / 2.13.2+
Fix from $1,950 2023-09-27
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Subscription Manager HIGH 7.8
CVE-2023-3899

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…

Fix: 1.28.39 / 1.29.37+
Fix from $1,950 2023-08-23
Device Mapper Multipath HIGH 7.8
CVE-2022-3787

A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in…

Mitigation only
Fix from $1,950 2023-03-29
Certificate System MEDIUM 5.7
CVE-2022-2393

A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.…

Fix: after 10.12.4
Fix from $1,600 2022-07-14
Cloudforms HIGH 8.1
CVE-2020-25716

A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a…

Fix: 5.11.10.1+
Fix from $1,950 2021-06-07
Openstack Selinux MEDIUM 6.5
CVE-2020-1690

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri…

Fix: 0.8.24+
Fix from $1,600 2021-06-07
Satellite MEDIUM 6.5
CVE-2020-10716

A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a mali…

Fix: 4.0.3.4+
Fix from $1,600 2021-05-27
Enterprise Linux HIGH 7.5
CVE-2020-27779

A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove …

Fix: 2.06+
Fix from $1,950 2021-03-03
Undertow CRITICAL 9.8
CVE-2020-1745

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final …

Fix: after 2.0.29
Fix from $2,300 2020-04-28
Satellite CRITICAL 9.1
CVE-2019-17631

From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil…

Fix: after 0.16.0
Fix from $2,300 2019-10-17
Enterprise Linux HIGH 7.0
CVE-2019-3842

In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p…

Fix: after 241
Fix from $1,950 2019-04-09
Satellite HIGH 7.2
CVE-2018-14666

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered…

Fix: after 6.4
Fix from $1,950 2019-01-22
Ceph MEDIUM 5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Keycloak HIGH 8.1
CVE-2018-14637

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…

Fix: 4.6.0+
Fix from $1,950 2018-11-30
Enterprise Linux Server HIGH 7.8
CVE-2016-7035

An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…

Fix: after 1.1.16
Fix from $1,950 2018-09-10
Cloudforms Management Engine HIGH 8.8
CVE-2016-7071

It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent…

Fix: 5.6.2.2 / 5.7.0.7+
Fix from $1,950 2018-09-10
Jboss Fuse CRITICAL 9.0
CVE-2017-2589

It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored …

Mitigation only
Fix from $2,300 2018-07-26
Ceph Storage HIGH 8.1
CVE-2018-10861

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…

Patch available
Fix from $1,950 2018-07-10
Setup MEDIUM 5.3
CVE-2018-1113

setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec…

Fix: 2.11.4+
Fix from $1,600 2018-07-03
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Pagure HIGH 7.5
CVE-2017-1002151

Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization

Fix: after 3.3
Fix from $1,950 2017-09-14