Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Certificate ValidationCWE-295 × clear
HIGH 8.3 CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows … Openshift Container Platform after 4.22.1 Fix from $1,9502026-06-22 HIGH 8.2 CVE-2026-4740 A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubern… Advanced Cluster Management For Kubernetes No fix yet Fix from $1,9502026-04-07 MEDIUM 5.3 CVE-2025-32989 A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the Certificate Transparency (CT) Signed Certificate Timestamp (SCT) exten… Openshift Container Platform Mitigation only Fix from $1,6002025-07-10 MEDIUM 5.9 CVE-2024-8285 A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails … Kroxylicious Mitigation only Fix from $1,6002024-08-30 HIGH 8.1 CVE-2024-8007 A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker … Openstack Platform Mitigation only Fix from $1,9502024-08-21 HIGH 7.4 CVE-2023-4586 A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,… Data Grid Mitigation only Fix from $1,9502023-10-04 HIGH 7.1 CVE-2023-2422 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien… Keycloak Mitigation only Fix from $1,9502023-10-04 MEDIUM 6.5 CVE-2023-1664 A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is… Build Of Quarkus Mitigation only Fix from $1,6002023-05-26 MEDIUM 5.5 CVE-2023-1055 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib… Directory Server Mitigation only Fix from $1,6002023-02-27 MEDIUM 6.5 CVE-2022-1632 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-01 MEDIUM 5.4 CVE-2020-35509 A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because… Keycloak Mitigation only Fix from $1,6002022-08-23 CRITICAL 9.1 CVE-2014-8164 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud… Cloudforms Management Engine Mitigation only Fix from $2,3002022-07-06 HIGH 8.1 CVE-2022-0759 A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeco… Kubeclient 4.9.3+ Fix from $1,9502022-03-25 HIGH 7.5 CVE-2021-3698 A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Dae… Enterprise Linux 260+ Fix from $1,9502022-03-10 HIGH 8.1 CVE-2021-3935 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first e… Enterprise Linux 1.16.1+ Fix from $1,9502021-11-22 MEDIUM 5.4 CVE-2020-25680 A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v… Jboss Core Services Httpd Mitigation only Fix from $1,6002021-01-07 MEDIUM 5.9 CVE-2020-1758 A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s… Keycloak 10.0.0+ Fix from $1,6002020-05-15 HIGH 7.5 CVE-2013-0264 An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary … Mrg Management Console Patch available Fix from $1,9502019-12-30 CRITICAL 9.8 CVE-2019-14910 A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA… Keycloak Mitigation only Fix from $2,3002019-12-05 MEDIUM 5.3 CVE-2011-2207 dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte… Enterprise Linux 2.1.0+ Fix from $1,6002019-11-27 MEDIUM 5.9 CVE-2014-8167 vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack Enterprise Virtualization Mitigation only Fix from $1,6002019-11-13 MEDIUM 5.9 CVE-2013-2255 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert… Openstack Mitigation only Fix from $1,6002019-11-01 HIGH 7.4 CVE-2019-14823 A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly tru… Enterprise Linux after 4.6.2 Fix from $1,9502019-10-14 HIGH 8.1 CVE-2019-3890 It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential … Enterprise Linux 3.31.3+ Fix from $1,9502019-08-01 MEDIUM 5.4 CVE-2017-7513 It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fiel… Satellite Mitigation only Fix from $1,6002018-08-22 MEDIUM 5.4 CVE-2018-10894 It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to acce… Keycloak Patch available Fix from $1,6002018-08-01 MEDIUM 5.3 CVE-2017-2623 It was discovered that rpm-ostree and rpm-ostree-client before 2017.3 fail to properly check GPG signatures on packages when doing layering. Packages… Enterprise Linux 2017.3+ Fix from $1,6002018-07-27 HIGH 7.5 CVE-2017-2639 It was found that CloudForms does not verify that the server hostname matches the domain name in the certificate when using a custom CA and communica… Cloudforms Mitigation only Fix from $1,9502018-07-27 MEDIUM 6.5 CVE-2017-7562 An authentication bypass flaw was found in the way krb5's certauth interface before 1.16.1 handled the validation of client certificates. A remote at… Enterprise Linux 1.16.1+ Fix from $1,6002018-07-26 MEDIUM 5.9 CVE-2015-1777 rhnreg_ks in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Gluster Storage 2.1 and Enterprise Linux (RHEL) 5, 6, and 7 does not prop… Rhn Client Tools Mitigation only Fix from $1,6002018-04-12