Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Missing AuthenticationCWE-306 × clear
Build Of Keycloak HIGH 8.1
CVE-2026-2603

A flaw was found in Keycloak. A remote attacker could bypass security controls by sending a valid SAML response from an external Identity Provider (I…

Mitigation only
Fix from $1,950 2026-03-18
Ai Inference Server MEDIUM 5.3
CVE-2025-6920

A flaw was found in the authentication enforcement mechanism of a model inference API in ai-inference-server. All /v1/* endpoints are expected to enf…

Mitigation only
Fix from $1,600 2025-07-01
Openshift Container Platform MEDIUM 6.5
CVE-2024-7079

A flaw was found in the Openshift console. The /API/helm/verify endpoint is tasked to fetch and verify the installation of a Helm chart from a URI th…

Mitigation only
Fix from $1,600 2024-07-24
Fedora Coreos MEDIUM 5.5
CVE-2022-3675

Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the…

Fix: 37.20221031.1.0+
Fix from $1,600 2022-11-03
Satellite HIGH 8.0
CVE-2021-3589

An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run Ansible jobs can access host…

Fix: 7.1.0+
Fix from $1,950 2022-03-23
3scale MEDIUM 5.4
CVE-2020-25634

A flaw was found in Red Hat 3scale’s API docs URL, where it is accessible without credentials. This flaw allows an attacker to view sensitive informa…

Fix: 2.10.0+
Fix from $1,600 2021-05-26
Keycloak MEDIUM 6.8
CVE-2021-20262

A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an …

Mitigation only
Fix from $1,600 2021-03-09
Openshift Installer HIGH 8.1
CVE-2021-20198

A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Pl…

Fix: 0.9.0-master.0.20210125200451-95101da940b0+
Fix from $1,950 2021-02-23
Etcd MEDIUM 6.5
CVE-2020-15136

In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gatew…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-06
Enterprise Virtualization HIGH 7.5
CVE-2015-5201

VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as pack…

Fix: 3.5.6 / 6-6.7-20151117.0+
Fix from $1,950 2020-02-25
Openstack HIGH 7.5
CVE-2013-1793

openstack-utils openstack-db has insecure password creation

Mitigation only
Fix from $1,950 2019-12-10
Satellite MEDIUM 6.5
CVE-2019-10198

An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, w…

Fix: 0.15.7+
Fix from $1,600 2019-07-31
Cloudforms Management Engine MEDIUM 5.3
CVE-2017-15123

A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users onl…

Fix: after 5.10
Fix from $1,600 2019-06-12
Openshift Container Platform CRITICAL 9.8
CVE-2019-3899

It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This i…

Mitigation only
Fix from $2,300 2019-04-22
Openstack CRITICAL 10.0
CVE-2017-2637

A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable libvirtd based live-migration. Libvirtd is deployed…

Mitigation only
Fix from $2,300 2018-07-26
Jboss Data Grid MEDIUM 6.5
CVE-2017-2638

It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability…

Fix: 9.0.0+
Fix from $1,600 2018-07-16