Vulnerability index

Browse CVEs

23 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
MEDIUM 6.5 CVE-2026-18207 A flaw was found in the client policy enforcement mechanism of Keycloak. The issue occurs when the system checks group membership by name instead of … Build Of Keycloak No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2023-0456 A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to a mismatched token from a separate realm. This coul… Apicast 2.12.2 / 2.13.2+ Fix from $1,9502023-09-27 HIGH 7.5 CVE-2023-0813 A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic… Network Observability Mitigation only Fix from $1,9502023-09-15 HIGH 7.8 CVE-2023-3899 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red… Subscription Manager 1.28.39 / 1.29.37+ Fix from $1,9502023-08-23 HIGH 7.8 CVE-2022-3787 A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows local users to obtain root access, exploited alone or in… Device Mapper Multipath Mitigation only Fix from $1,9502023-03-29 MEDIUM 5.7 CVE-2022-2393 A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.… Certificate System after 10.12.4 Fix from $1,6002022-07-14 HIGH 8.1 CVE-2020-25716 A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is possible. An attacker with a… Cloudforms 5.11.10.1+ Fix from $1,9502021-06-07 MEDIUM 6.5 CVE-2020-1690 An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from pri… Openstack Selinux 0.8.24+ Fix from $1,6002021-06-07 MEDIUM 6.5 CVE-2020-10716 A flaw was found in Red Hat Satellite's Job Invocation, where the "User Input" entry was not properly restricted to the view. This flaw allows a mali… Satellite 4.0.3.4+ Fix from $1,6002021-05-27 HIGH 7.5 CVE-2020-27779 A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove … Enterprise Linux 2.06+ Fix from $1,9502021-03-03 CRITICAL 9.8 CVE-2020-1745 A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final … Undertow after 2.0.29 Fix from $2,3002020-04-28 CRITICAL 9.1 CVE-2019-17631 From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privil… Satellite after 0.16.0 Fix from $2,3002019-10-17 HIGH 7.0 CVE-2019-3842 In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is p… Enterprise Linux after 241 Fix from $1,9502019-04-09 HIGH 7.2 CVE-2018-14666 An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered… Satellite after 6.4 Fix from $1,9502019-01-22 MEDIUM 5.7 CVE-2018-14662 It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d… Ceph 13.2.4+ Fix from $1,6002019-01-15 HIGH 8.1 CVE-2018-14637 The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th… Keycloak 4.6.0+ Fix from $1,9502018-11-30 HIGH 7.8 CVE-2016-7035 An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou… Enterprise Linux Server after 1.1.16 Fix from $1,9502018-09-10 HIGH 8.8 CVE-2016-7071 It was found that the CloudForms before 5.6.2.2, and 5.7.0.7 did not properly apply permissions controls to VM IDs passed by users. A remote, authent… Cloudforms Management Engine 5.6.2.2 / 5.7.0.7+ Fix from $1,9502018-09-10 CRITICAL 9.0 CVE-2017-2589 It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies are stored … Jboss Fuse Mitigation only Fix from $2,3002018-07-26 HIGH 8.1 CVE-2018-10861 A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po… Ceph Storage Patch available Fix from $1,9502018-07-10 MEDIUM 5.3 CVE-2018-1113 setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates sec… Setup 2.11.4+ Fix from $1,6002018-07-03 HIGH 7.2 CVE-2017-12160 It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit… Keycloak Mitigation only Fix from $1,9502017-10-26 HIGH 7.5 CVE-2017-1002151 Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization Pagure after 3.3 Fix from $1,9502017-09-14