Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.3
CVE-2019-14909
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…
Keycloak
Mitigation only
MEDIUM 6.5
CVE-2019-14856
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
Ansible
2.6.20 / 2.7.14+
MEDIUM 5.4
CVE-2019-3884
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namesp…
Openshift
Mitigation only
MEDIUM 5.9
CVE-2019-10150
It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during…
Openshift Container Platform
after 4.1
MEDIUM 5.5
CVE-2019-10157
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel l…
Keycloak
4.8.3 / 7.3.2+
HIGH 8.1
CVE-2018-16886
etcd versions 3.2.x before 3.2.26 and 3.3.x before 3.3.11 are vulnerable to an improper authentication issue when role-based access control (RBAC) is…
Enterprise Linux Desktop
3.2.26 / 3.3.11+
HIGH 8.1
CVE-2018-14637
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit th…
Keycloak
4.6.0+
MEDIUM 6.5
CVE-2016-2125EPSS 9%
It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos authentication. A service to wh…
Gluster Storage
4.3.13 / 4.4.8+
HIGH 8.1
CVE-2016-8609
It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing …
Keycloak
2.3.0+
MEDIUM 6.5
CVE-2017-7562
An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…
Enterprise Linux
1.16.1+
MEDIUM 6.5
CVE-2017-2638
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…
Jboss Data Grid
9.0.0+
HIGH 8.1
CVE-2018-10861
A flaw was found in the way ceph mon handles user requests. Any authenticated ceph user having read access to ceph can delete, create ceph storage po…
Ceph Storage
Patch available
HIGH 7.5
CVE-2018-1128
It was found that cephx authentication protocol did not verify ceph clients correctly and was vulnerable to replay attack. Any attacker having access…
Ceph Storage
after 13.2.1
MEDIUM 6.5
CVE-2018-1129
A flaw was found in the way signature calculation was handled by cephx authentication protocol. An attacker having access to ceph cluster network who…
Ceph Storage
Patch available
CRITICAL 9.8
CVE-2018-1085
openshift-ansible before versions 3.9.23, 3.7.46 deploys a misconfigured etcd file that causes the SSL client certificate authentication to be disabl…
Openshift Container Platform
3.9.31+
CRITICAL 9.8
CVE-2018-10683
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successful…
Wildfly
No fix yet
MEDIUM 5.5
CVE-2018-1106
An authentication bypass flaw has been found in PackageKit before 1.1.10 that allows users without administrator privileges to install signed package…
Enterprise Linux Desktop
Mitigation only
MEDIUM 5.9
CVE-2017-12196
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that…
Undertow
after 1.4.18
CRITICAL 9.8
CVE-2018-7750EPSS 27%
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2…
Ansible Engine
Patch available
CRITICAL 9.8
CVE-2014-0121
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.
Jboss Fuse
after 1.2.2
HIGH 7.2
CVE-2017-12160
It was found that Keycloak oauth would permit an authenticated resource to obtain an access/refresh token pair from the authentication server, permit…
Keycloak
Mitigation only
MEDIUM 5.5
CVE-2016-5410
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (…
Enterprise Linux Desktop
after 0.4.3.2
MEDIUM 5.0
CVE-2013-6470
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…
Openstack
Mitigation only
HIGH 7.5
CVE-2014-0188
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…
Openshift
after 2.0.5
MEDIUM 5.8
CVE-2012-0062
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration…
Jboss Operations Network
after 2.4.1
MEDIUM 5.8
CVE-2012-1100
Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credenti…
Jboss Operations Network
after 2.4.1
HIGH 9.3
CVE-2013-6439
Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…
Subscription Asset Manager
No fix yet
MEDIUM 5.0
CVE-2013-2056
The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al…
Satellite
Mitigation only
HIGH 7.5
CVE-2013-0314
The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…
Jboss Enterprise Portal Platform
Mitigation only
MEDIUM 6.8
CVE-2012-0874EPSS 14%
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E…
Jboss Enterprise Application Platform
after 5.3.0