Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
Openshift Container Platform HIGH 8.3
CVE-2026-54100

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows …

Fix: after 4.22.1
Fix from $1,950 2026-06-22
Advanced Cluster Management For Kubernetes HIGH 8.2
CVE-2026-4740

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern…

No fix yet
Fix from $1,950 2026-04-07
Openshift Container Platform MEDIUM 5.3
CVE-2025-32989

A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten…

Mitigation only
Fix from $1,600 2025-07-10
Kroxylicious MEDIUM 5.9
CVE-2024-8285

A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails …

Mitigation only
Fix from $1,600 2024-08-30
Openstack Platform HIGH 8.1
CVE-2024-8007

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker …

Mitigation only
Fix from $1,950 2024-08-21
Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Keycloak HIGH 7.1
CVE-2023-2422

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien…

Mitigation only
Fix from $1,950 2023-10-04
Build Of Quarkus MEDIUM 6.5
CVE-2023-1664

A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is…

Mitigation only
Fix from $1,600 2023-05-26
Directory Server MEDIUM 5.5
CVE-2023-1055

A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib…

Mitigation only
Fix from $1,600 2023-02-27
Ansible Automation Platform MEDIUM 6.5
CVE-2022-1632

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv…

Mitigation only
Fix from $1,600 2022-09-01
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Cloudforms Management Engine CRITICAL 9.1
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…

Mitigation only
Fix from $2,300 2022-07-06
Kubeclient HIGH 8.1
CVE-2022-0759

A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco…

Fix: 4.9.3+
Fix from $1,950 2022-03-25
Enterprise Linux HIGH 7.5
CVE-2021-3698

A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae…

Fix: 260+
Fix from $1,950 2022-03-10
Enterprise Linux HIGH 8.1
CVE-2021-3935

When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e…

Fix: 1.16.1+
Fix from $1,950 2021-11-22
Jboss Core Services Httpd MEDIUM 5.4
CVE-2020-25680

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v…

Mitigation only
Fix from $1,600 2021-01-07
Keycloak MEDIUM 5.9
CVE-2020-1758

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s…

Fix: 10.0.0+
Fix from $1,600 2020-05-15
Mrg Management Console HIGH 7.5
CVE-2013-0264

An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary …

Patch available
Fix from $1,950 2019-12-30
Keycloak CRITICAL 9.8
CVE-2019-14910

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…

Mitigation only
Fix from $2,300 2019-12-05
Enterprise Linux MEDIUM 5.3
CVE-2011-2207

dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…

Fix: 2.1.0+
Fix from $1,600 2019-11-27
Enterprise Virtualization MEDIUM 5.9
CVE-2014-8167

vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack

Mitigation only
Fix from $1,600 2019-11-13
Openstack MEDIUM 5.9
CVE-2013-2255

HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…

Mitigation only
Fix from $1,600 2019-11-01
Enterprise Linux HIGH 7.4
CVE-2019-14823

A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru…

Fix: after 4.6.2
Fix from $1,950 2019-10-14
Enterprise Linux HIGH 8.1
CVE-2019-3890

It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential …

Fix: 3.31.3+
Fix from $1,950 2019-08-01
Satellite MEDIUM 5.4
CVE-2017-7513

It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel…

Mitigation only
Fix from $1,600 2018-08-22
Keycloak MEDIUM 5.4
CVE-2018-10894

It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce…

Patch available
Fix from $1,600 2018-08-01
Enterprise Linux MEDIUM 5.3
CVE-2017-2623

It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages…

Fix: 2017.3+
Fix from $1,600 2018-07-27
Cloudforms HIGH 7.5
CVE-2017-2639

It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica…

Mitigation only
Fix from $1,950 2018-07-27
Enterprise Linux MEDIUM 6.5
CVE-2017-7562

An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at…

Fix: 1.16.1+
Fix from $1,600 2018-07-26
Rhn Client Tools MEDIUM 5.9
CVE-2015-1777

rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop…

Mitigation only
Fix from $1,600 2018-04-12