Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 6.5 CVE-2025-12801 A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the privi… Openshift Container Platform Mitigation only Fix from $1,6002026-03-04 MEDIUM 5.5 CVE-2022-3146 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3101 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 CRITICAL 9.8 CVE-2020-27836 A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker… Openshift Container Platform Patch available Fix from $2,3002022-08-22 MEDIUM 6.5 CVE-2022-1655 An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without … Openstack Mitigation only Fix from $1,6002022-07-22 MEDIUM 5.5 CVE-2014-0068 It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. Openshift Origin Node Util Mitigation only Fix from $1,6002022-06-30 MEDIUM 6.3 CVE-2021-3631 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access fil… Libvirt 7.5.0+ Fix from $1,6002022-03-02 MEDIUM 6.5 CVE-2021-3557 A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-serve… Openshift Gitops 1.1.1+ Fix from $1,6002022-02-16 HIGH 7.0 CVE-2020-1742 An insecure modification vulnerability flaw was found in containers using nmstate/kubernetes-nmstate-handler. An attacker with access to the containe… Openshift Virtualization 2.3.0+ Fix from $1,9502021-06-07 MEDIUM 5.5 CVE-2020-14335 A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows… Satellite Mitigation only Fix from $1,6002021-06-02 HIGH 7.5 CVE-2021-31918 A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update a… Openstack Mitigation only Fix from $1,9502021-05-06 MEDIUM 5.5 CVE-2020-10762 An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes … Gluster Block 0.5.1+ Fix from $1,6002020-11-24 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 HIGH 7.8 CVE-2020-1709 A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd f… Openshift 4.3+ Fix from $1,9502020-03-20 HIGH 7.0 CVE-2020-1707 A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pas… Openshift 4.3+ Fix from $1,9502020-03-20 HIGH 7.0 CVE-2020-1705 A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab… Template Service Broker Operator 4.3.0+ Fix from $1,9502020-03-19 HIGH 7.0 CVE-2020-1706 It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th… Openshift Container Platform Mitigation only Fix from $1,9502020-03-09 HIGH 7.8 CVE-2020-1704 An insecure modification vulnerability in the /etc/passwd file was found in all versions of OpenShift ServiceMesh (maistra) before 1.0.8 in the opens… Openshift Service Mesh 1.0.8+ Fix from $1,9502020-02-17 MEDIUM 5.5 CVE-2019-19341 A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both … Ansible Tower 3.6.2+ Fix from $1,6002019-12-19 MEDIUM 6.5 CVE-2019-14824 A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,… Enterprise Linux Mitigation only Fix from $1,6002019-11-08 MEDIUM 5.5 CVE-2019-3866 An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world… Openstack Mistral Mitigation only Fix from $1,6002019-11-08 HIGH 8.0 CVE-2010-0737 A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u… Jboss Operations Network 2.3.1+ Fix from $1,9502019-10-30 MEDIUM 5.3 CVE-2019-6465 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 … Enterprise Linux after 9.13.6 Fix from $1,6002019-10-09 HIGH 8.8 CVE-2019-10132 A vulnerability was found in libvirt >= 4.1.0 in the virtlockd-admin.socket and virtlogd-admin.socket systemd units. A missing SocketMode configurati… Libvirt after 4.1.0 Fix from $1,9502019-05-22 MEDIUM 5.7 CVE-2018-14662 It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d… Ceph 13.2.4+ Fix from $1,6002019-01-15 MEDIUM 5.5 CVE-2016-2121 A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat… Openstack Mitigation only Fix from $1,6002018-10-31 MEDIUM 5.0 CVE-2018-14650 It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada… Enterprise Linux Desktop Patch available Fix from $1,6002018-09-27 HIGH 8.1 CVE-2017-2590 A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while mod… Enterprise Linux 4.4.0+ Fix from $1,9502018-07-27 MEDIUM 5.5 CVE-2017-12167 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role ma… Jboss Enterprise Application Platform 7.0.9+ Fix from $1,6002018-07-26 HIGH 7.5 CVE-2018-10869 redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file access… Certification Mitigation only Fix from $1,9502018-07-19