Vulnerability index

Browse CVEs

66 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.4 CVE-2026-18651 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t… Directory Server No fix yet Fix from $1,6002026-08-03 HIGH 8.1 CVE-2026-18215 Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 HIGH 7.8 CVE-2026-12112 A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active ad… Satellite Mitigation only Fix from $1,9502026-06-23 HIGH 7.5 CVE-2026-46579 A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Cli… Openshift Container Platform Mitigation only Fix from $1,9502026-05-29 MEDIUM 5.4 CVE-2025-3910 A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumven… Build Of Keycloak 26.0.11+ Fix from $1,6002025-04-29 MEDIUM 5.3 CVE-2024-9683 A vulnerability was found in Quay, which allows successful authentication even when a truncated password version is provided. This flaw affects the a… Quay Mitigation only Fix from $1,6002024-10-17 CRITICAL 9.8 CVE-2024-7012 An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configura… Satellite Mitigation only Fix from $2,3002024-09-04 CRITICAL 9.8 CVE-2024-7923 An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the puppet-pulpcore… Satellite Mitigation only Fix from $2,3002024-09-04 MEDIUM 5.3 CVE-2024-6535 A flaw was found in Skupper. When Skupper is initialized with the console-enabled and with console-auth set to Openshift, it configures the openshift… Service Interconnect Mitigation only Fix from $1,6002024-07-17 HIGH 8.8 CVE-2023-6787 A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijack… Build Of Keycloak 22.0.10 / 24.0.3+ Fix from $1,9502024-04-25 MEDIUM 5.5 CVE-2023-4641 A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, … Codeready Linux Builder Mitigation only Fix from $1,6002023-12-27 MEDIUM 6.6 CVE-2023-40660 A flaw was found in OpenSC packages that allow a potential PIN bypass. When a token/card is authenticated by one process, it can perform cryptographi… Enterprise Linux after 0.23.0 Fix from $1,6002023-11-06 HIGH 7.5 CVE-2023-0813 A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic… Network Observability Mitigation only Fix from $1,9502023-09-15 MEDIUM 5.0 CVE-2023-0264 A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could ob… Keycloak 7.6.2 / 18.0.6+ Fix from $1,6002023-08-04 MEDIUM 6.5 CVE-2023-0105 A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker … Keycloak Mitigation only Fix from $1,6002023-01-13 HIGH 7.5 CVE-2021-3632 A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered… Keycloak 7.4.9 / 15.1.0+ Fix from $1,9502022-08-26 MEDIUM 6.5 CVE-2021-3979 A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo… Ceph Storage Patch available Fix from $1,6002022-08-25 MEDIUM 6.8 CVE-2021-3827 A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at… Keycloak 18.0.0+ Fix from $1,6002022-08-23 MEDIUM 6.5 CVE-2022-0996 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. 389 Directory Server No fix yet Fix from $1,6002022-03-23 CRITICAL 9.8 CVE-2021-31917 A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An attacker could bypass authenticat… Data Grid 11.0.12 / 12.1.4+ Fix from $2,3002021-09-21 HIGH 7.5 CVE-2020-14380 An account takeover flaw was found in Red Hat Satellite 6.7.2 onward. A potential attacker with proper authentication to the relevant external authen… Satellite Mitigation only Fix from $1,9502021-06-02 MEDIUM 5.3 CVE-2021-3424 A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself… Single Sign On Mitigation only Fix from $1,6002021-06-01 HIGH 7.1 CVE-2020-10709 A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authen… Ansible Tower 3.5.6 / 3.6.4+ Fix from $1,9502021-05-27 HIGH 7.2 CVE-2021-20288 An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz… Ceph Storage 14.2.21+ Fix from $1,9502021-04-15 MEDIUM 6.5 CVE-2020-27838EPSS 18% A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like cli… Keycloak 13.0.0+ Fix from $1,6002021-03-08 MEDIUM 6.5 CVE-2020-14299 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox Secur… Jboss Enterprise Application Platform 5.0.3+ Fix from $1,6002020-10-16 MEDIUM 6.5 CVE-2020-15136 In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew… Etcd 3.3.23 / 3.4.10+ Fix from $1,6002020-08-06 HIGH 8.8 CVE-2020-1718 A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the … Jboss Fuse 8.0.0+ Fix from $1,9502020-05-12 HIGH 7.3 CVE-2020-8595 Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1.3.7, and 1.4 through 1.4.3 allows authentication bypass. The Authentication Policy exact… Openshift Service Mesh after 1.4.3 Fix from $1,9502020-02-12 CRITICAL 9.8 CVE-2019-14910 A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA… Keycloak Mitigation only Fix from $2,3002019-12-05