Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Openshift Container Platform MEDIUM 6.5
CVE-2025-12801

A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi…

Mitigation only
Fix from $1,600 2026-03-04
Openstack MEDIUM 5.5
CVE-2022-3146

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openstack MEDIUM 5.5
CVE-2022-3101

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T…

Mitigation only
Fix from $1,600 2023-03-23
Openshift Container Platform CRITICAL 9.8
CVE-2020-27836

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…

Patch available
Fix from $2,300 2022-08-22
Openstack MEDIUM 6.5
CVE-2022-1655

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without …

Mitigation only
Fix from $1,600 2022-07-22
Openshift Origin Node Util MEDIUM 5.5
CVE-2014-0068

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

Mitigation only
Fix from $1,600 2022-06-30
Libvirt MEDIUM 6.3
CVE-2021-3631

A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil…

Fix: 7.5.0+
Fix from $1,600 2022-03-02
Openshift Gitops MEDIUM 6.5
CVE-2021-3557

A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve…

Fix: 1.1.1+
Fix from $1,600 2022-02-16
Openshift Virtualization HIGH 7.0
CVE-2020-1742

An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe…

Fix: 2.3.0+
Fix from $1,950 2021-06-07
Satellite MEDIUM 5.5
CVE-2020-14335

A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows…

Mitigation only
Fix from $1,600 2021-06-02
Openstack HIGH 7.5
CVE-2021-31918

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a…

Mitigation only
Fix from $1,950 2021-05-06
Gluster Block MEDIUM 5.5
CVE-2020-10762

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …

Fix: 0.5.1+
Fix from $1,600 2020-11-24
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Openshift HIGH 7.8
CVE-2020-1709

A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd f…

Fix: 4.3+
Fix from $1,950 2020-03-20
Openshift HIGH 7.0
CVE-2020-1707

A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pas…

Fix: 4.3+
Fix from $1,950 2020-03-20
Template Service Broker Operator HIGH 7.0
CVE-2020-1705

A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab…

Fix: 4.3.0+
Fix from $1,950 2020-03-19
Openshift Container Platform HIGH 7.0
CVE-2020-1706

It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…

Mitigation only
Fix from $1,950 2020-03-09
Openshift Service Mesh HIGH 7.8
CVE-2020-1704

An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens…

Fix: 1.0.8+
Fix from $1,950 2020-02-17
Ansible Tower MEDIUM 5.5
CVE-2019-19341

A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both …

Fix: 3.6.2+
Fix from $1,600 2019-12-19
Enterprise Linux MEDIUM 6.5
CVE-2019-14824

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…

Mitigation only
Fix from $1,600 2019-11-08
Openstack Mistral MEDIUM 5.5
CVE-2019-3866

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…

Mitigation only
Fix from $1,600 2019-11-08
Jboss Operations Network HIGH 8.0
CVE-2010-0737

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u…

Fix: 2.3.1+
Fix from $1,950 2019-10-30
Enterprise Linux MEDIUM 5.3
CVE-2019-6465

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 …

Fix: after 9.13.6
Fix from $1,600 2019-10-09
Libvirt HIGH 8.8
CVE-2019-10132

A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati…

Fix: after 4.1.0
Fix from $1,950 2019-05-22
Ceph MEDIUM 5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
Enterprise Linux Desktop MEDIUM 5.0
CVE-2018-14650

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada…

Patch available
Fix from $1,600 2018-09-27
Enterprise Linux HIGH 8.1
CVE-2017-2590

A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod…

Fix: 4.4.0+
Fix from $1,950 2018-07-27
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2017-12167

It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma…

Fix: 7.0.9+
Fix from $1,600 2018-07-26
Certification HIGH 7.5
CVE-2018-10869

redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access…

Mitigation only
Fix from $1,950 2018-07-19