Vulnerability index

Browse CVEs

25 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Insufficiently Protected CredentialsCWE-522 × clear
MEDIUM 6.5 CVE-2026-16104 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl… Build Of Keycloak No fix yet Fix from $1,6002026-07-17 MEDIUM 5.5 CVE-2023-1633 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce… Openstack Platform Mitigation only Fix from $1,6002023-09-24 MEDIUM 5.5 CVE-2022-3644 The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the… Ansible Automation Platform No fix yet Fix from $1,6002022-10-25 HIGH 7.5 CVE-2019-14840 A flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentials. Decision Manager No fix yet Fix from $1,9502022-10-17 HIGH 7.5 CVE-2021-3513 A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error … Keycloak 13.0.0+ Fix from $1,9502022-08-22 MEDIUM 5.5 CVE-2021-3681 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex… Ansible Automation Platform Mitigation only Fix from $1,6002022-04-18 MEDIUM 5.4 CVE-2020-27839 A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s loca… Ceph 14.2.17 / 15.2.9+ Fix from $1,6002021-05-26 HIGH 8.8 CVE-2021-3528 A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake… Noobaa Operator 5.7.0+ Fix from $1,9502021-05-13 MEDIUM 6.3 CVE-2019-10225 A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the… Openshift Mitigation only Fix from $1,6002021-03-19 HIGH 8.8 CVE-2021-3344 A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into t… Openshift Builder 4.5.33 / 4.6.16+ Fix from $1,9502021-03-16 HIGH 7.1 CVE-2020-27781 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open S… Ceph 14.2.16 / 15.2.8+ Fix from $1,9502020-12-18 HIGH 8.8 CVE-2020-14334 A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com… Satellite Mitigation only Fix from $1,9502020-07-31 HIGH 7.5 CVE-2020-10752 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa… Openshift Container Platform Patch available Fix from $1,9502020-06-12 MEDIUM 6.5 CVE-2020-10755 An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o… Openstack Cinder 14.1.0 / 15.2.0+ Fix from $1,6002020-06-10 MEDIUM 5.5 CVE-2014-4659 Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunisti… Ansible 1.5.5+ Fix from $1,6002020-02-20 MEDIUM 5.5 CVE-2014-4660 Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local user… Ansible 1.5.5+ Fix from $1,6002020-02-20 MEDIUM 6.3 CVE-2019-10205 A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay … Quay Mitigation only Fix from $1,6002020-01-02 MEDIUM 5.5 CVE-2014-0241 rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable Satellite Mitigation only Fix from $1,6002019-12-13 MEDIUM 5.9 CVE-2019-10214 The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Con… Openshift Container Platform Patch available Fix from $1,6002019-11-25 MEDIUM 6.5 CVE-2019-10206 ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by … Ansible 2.6.19 / 2.7.13+ Fix from $1,6002019-11-22 MEDIUM 5.5 CVE-2013-4423 CloudForms stores user passwords in recoverable format Cloudforms Mitigation only Fix from $1,6002019-11-04 HIGH 8.8 CVE-2017-7510 In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface. Ovirt Engine Mitigation only Fix from $1,9502019-03-25 MEDIUM 5.5 CVE-2018-12383 If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is… Enterprise Linux Desktop No fix yet Fix from $1,6002018-10-18 HIGH 7.2 CVE-2018-1074 ovirt-engine API and administration web portal before versions 4.2.2.5, 4.1.11.2 is vulnerable to an exposure of Power Management credentials, includ… Enterprise Virtualization after 4.1.11.1 Fix from $1,9502018-04-26 HIGH 8.8 CVE-2016-9593 foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able… Satellite 1.15.0+ Fix from $1,9502018-04-16