Vulnerability index

Browse CVEs

66 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Directory Server MEDIUM 5.4
CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t…

No fix yet
Fix from $1,600 2026-08-03
Build Of Keycloak HIGH 8.1
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove…

No fix yet
Fix from $1,950 2026-07-31
Satellite HIGH 7.8
CVE-2026-12112

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad…

Mitigation only
Fix from $1,950 2026-06-23
Openshift Container Platform HIGH 7.5
CVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli…

Mitigation only
Fix from $1,950 2026-05-29
Build Of Keycloak MEDIUM 5.4
CVE-2025-3910

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven…

Fix: 26.0.11+
Fix from $1,600 2025-04-29
Quay MEDIUM 5.3
CVE-2024-9683

A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a…

Mitigation only
Fix from $1,600 2024-10-17
Satellite CRITICAL 9.8
CVE-2024-7012

An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura…

Mitigation only
Fix from $2,300 2024-09-04
Satellite CRITICAL 9.8
CVE-2024-7923

An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore…

Mitigation only
Fix from $2,300 2024-09-04
Service Interconnect MEDIUM 5.3
CVE-2024-6535

A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift…

Mitigation only
Fix from $1,600 2024-07-17
Build Of Keycloak HIGH 8.8
CVE-2023-6787

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack…

Fix: 22.0.10 / 24.0.3+
Fix from $1,950 2024-04-25
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4641

A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, …

Mitigation only
Fix from $1,600 2023-12-27
Enterprise Linux MEDIUM 6.6
CVE-2023-40660

A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi…

Fix: after 0.23.0
Fix from $1,600 2023-11-06
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Keycloak MEDIUM 5.0
CVE-2023-0264

A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob…

Fix: 7.6.2 / 18.0.6+
Fix from $1,600 2023-08-04
Keycloak MEDIUM 6.5
CVE-2023-0105

A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker …

Mitigation only
Fix from $1,600 2023-01-13
Keycloak HIGH 7.5
CVE-2021-3632

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered…

Fix: 7.4.9 / 15.1.0+
Fix from $1,950 2022-08-26
Ceph Storage MEDIUM 6.5
CVE-2021-3979

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo…

Patch available
Fix from $1,600 2022-08-25
Keycloak MEDIUM 6.8
CVE-2021-3827

A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at…

Fix: 18.0.0+
Fix from $1,600 2022-08-23
389 Directory Server MEDIUM 6.5
CVE-2022-0996

A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.

No fix yet
Fix from $1,600 2022-03-23
Data Grid CRITICAL 9.8
CVE-2021-31917

A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat…

Fix: 11.0.12 / 12.1.4+
Fix from $2,300 2021-09-21
Satellite HIGH 7.5
CVE-2020-14380

An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen…

Mitigation only
Fix from $1,950 2021-06-02
Single Sign On MEDIUM 5.3
CVE-2021-3424

A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself…

Mitigation only
Fix from $1,600 2021-06-01
Ansible Tower HIGH 7.1
CVE-2020-10709

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen…

Fix: 3.5.6 / 3.6.4+
Fix from $1,950 2021-05-27
Ceph Storage HIGH 7.2
CVE-2021-20288

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…

Fix: 14.2.21+
Fix from $1,950 2021-04-15
Keycloak MEDIUM 6.5
CVE-2020-27838EPSS 18%

A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli…

Fix: 13.0.0+
Fix from $1,600 2021-03-08
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2020-14299

A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur…

Fix: 5.0.3+
Fix from $1,600 2020-10-16
Etcd MEDIUM 6.5
CVE-2020-15136

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-06
Jboss Fuse HIGH 8.8
CVE-2020-1718

A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the …

Fix: 8.0.0+
Fix from $1,950 2020-05-12
Openshift Service Mesh HIGH 7.3
CVE-2020-8595

Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact…

Fix: after 1.4.3
Fix from $1,950 2020-02-12
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05