Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-16104

A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl…

No fix yet
Fix from $1,600 2026-07-17
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24
Ansible Automation Platform MEDIUM 5.5
CVE-2022-3644

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the…

No fix yet
Fix from $1,600 2022-10-25
Decision Manager HIGH 7.5
CVE-2019-14840

A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials.

No fix yet
Fix from $1,950 2022-10-17
Keycloak HIGH 7.5
CVE-2021-3513

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error …

Fix: 13.0.0+
Fix from $1,950 2022-08-22
Ansible Automation Platform MEDIUM 5.5
CVE-2021-3681

A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex…

Mitigation only
Fix from $1,600 2022-04-18
Ceph MEDIUM 5.4
CVE-2020-27839

A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s loca…

Fix: 14.2.17 / 15.2.9+
Fix from $1,600 2021-05-26
Noobaa Operator HIGH 8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…

Fix: 5.7.0+
Fix from $1,950 2021-05-13
Openshift MEDIUM 6.3
CVE-2019-10225

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the…

Mitigation only
Fix from $1,600 2021-03-19
Openshift Builder HIGH 8.8
CVE-2021-3344

A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into t…

Fix: 4.5.33 / 4.6.16+
Fix from $1,950 2021-03-16
Ceph HIGH 7.1
CVE-2020-27781

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S…

Fix: 14.2.16 / 15.2.8+
Fix from $1,950 2020-12-18
Satellite HIGH 8.8
CVE-2020-14334

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com…

Mitigation only
Fix from $1,950 2020-07-31
Openshift Container Platform HIGH 7.5
CVE-2020-10752

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…

Patch available
Fix from $1,950 2020-06-12
Openstack Cinder MEDIUM 6.5
CVE-2020-10755

An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o…

Fix: 14.1.0 / 15.2.0+
Fix from $1,600 2020-06-10
Ansible MEDIUM 5.5
CVE-2014-4659

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Ansible MEDIUM 5.5
CVE-2014-4660

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user…

Fix: 1.5.5+
Fix from $1,600 2020-02-20
Quay MEDIUM 6.3
CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …

Mitigation only
Fix from $1,600 2020-01-02
Satellite MEDIUM 5.5
CVE-2014-0241

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Mitigation only
Fix from $1,600 2019-12-13
Openshift Container Platform MEDIUM 5.9
CVE-2019-10214

The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Con…

Patch available
Fix from $1,600 2019-11-25
Ansible MEDIUM 6.5
CVE-2019-10206

ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by …

Fix: 2.6.19 / 2.7.13+
Fix from $1,600 2019-11-22
Cloudforms MEDIUM 5.5
CVE-2013-4423

CloudForms stores user passwords in recoverable format

Mitigation only
Fix from $1,600 2019-11-04
Ovirt Engine HIGH 8.8
CVE-2017-7510

In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.

Mitigation only
Fix from $1,950 2019-03-25
Enterprise Linux Desktop MEDIUM 5.5
CVE-2018-12383

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is…

No fix yet
Fix from $1,600 2018-10-18
Enterprise Virtualization HIGH 7.2
CVE-2018-1074

ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ…

Fix: after 4.1.11.1
Fix from $1,950 2018-04-26
Satellite HIGH 8.8
CVE-2016-9593

foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able…

Fix: 1.15.0+
Fix from $1,950 2018-04-16