Vulnerability index

Browse CVEs

66 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Keycloak HIGH 8.3
CVE-2019-14909

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…

Mitigation only
Fix from $1,950 2019-12-04
Ansible MEDIUM 6.5
CVE-2019-14856

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Fix: 2.6.20 / 2.7.14+
Fix from $1,600 2019-11-26
Openshift MEDIUM 5.4
CVE-2019-3884

A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…

Mitigation only
Fix from $1,600 2019-08-01
Openshift Container Platform MEDIUM 5.9
CVE-2019-10150

It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…

Fix: after 4.1
Fix from $1,600 2019-06-12
Keycloak MEDIUM 5.5
CVE-2019-10157

It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…

Fix: 4.8.3 / 7.3.2+
Fix from $1,600 2019-06-12
Enterprise Linux Desktop HIGH 8.1
CVE-2018-16886

etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…

Fix: 3.2.26 / 3.3.11+
Fix from $1,950 2019-01-14
Keycloak HIGH 8.1
CVE-2018-14637

The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…

Fix: 4.6.0+
Fix from $1,950 2018-11-30
Gluster Storage MEDIUM 6.5
CVE-2016-2125EPSS 9%

It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…

Fix: 4.3.13 / 4.4.8+
Fix from $1,600 2018-10-31
Keycloak HIGH 8.1
CVE-2016-8609

It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing …

Fix: 2.3.0+
Fix from $1,950 2018-08-01
Enterprise Linux MEDIUM 6.5
CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…

Fix: 1.16.1+
Fix from $1,600 2018-07-26
Jboss Data Grid MEDIUM 6.5
CVE-2017-2638

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…

Fix: 9.0.0+
Fix from $1,600 2018-07-16
Ceph Storage HIGH 8.1
CVE-2018-10861

A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…

Patch available
Fix from $1,950 2018-07-10
Ceph Storage HIGH 7.5
CVE-2018-1128

It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access…

Fix: after 13.2.1
Fix from $1,950 2018-07-10
Ceph Storage MEDIUM 6.5
CVE-2018-1129

A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…

Patch available
Fix from $1,600 2018-07-10
Openshift Container Platform CRITICAL 9.8
CVE-2018-1085

openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…

Fix: 3.9.31+
Fix from $2,300 2018-06-15
Wildfly CRITICAL 9.8
CVE-2018-10683

An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…

No fix yet
Fix from $2,300 2018-05-09
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-1106

An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…

Mitigation only
Fix from $1,600 2018-04-23
Undertow MEDIUM 5.9
CVE-2017-12196

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…

Fix: after 1.4.18
Fix from $1,600 2018-04-18
Ansible Engine CRITICAL 9.8
CVE-2018-7750EPSS 27%

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…

Patch available
Fix from $2,300 2018-03-13
Jboss Fuse CRITICAL 9.8
CVE-2014-0121

The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.

Fix: after 1.2.2
Fix from $2,300 2017-12-29
Keycloak HIGH 7.2
CVE-2017-12160

It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…

Mitigation only
Fix from $1,950 2017-10-26
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-5410

firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (…

Fix: after 0.4.3.2
Fix from $1,600 2017-04-19
Openstack MEDIUM 5.0
CVE-2013-6470

The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…

Mitigation only
Fix from $1,600 2014-06-02
Openshift HIGH 7.5
CVE-2014-0188

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…

Fix: after 2.0.5
Fix from $1,950 2014-04-24
Jboss Operations Network MEDIUM 5.8
CVE-2012-0062

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Jboss Operations Network MEDIUM 5.8
CVE-2012-1100

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credenti…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Subscription Asset Manager HIGH 9.3
CVE-2013-6439

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…

No fix yet
Fix from $1,950 2013-12-23
Satellite MEDIUM 5.0
CVE-2013-2056

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al…

Mitigation only
Fix from $1,600 2013-07-31
Jboss Enterprise Portal Platform HIGH 7.5
CVE-2013-0314

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…

Mitigation only
Fix from $1,950 2013-04-12
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2012-0874EPSS 14%

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E…

Fix: after 5.3.0
Fix from $1,600 2013-02-05