Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Hard-coded CredentialsCWE-798 × clear
Enterprise Linux MEDIUM 5.9
CVE-2021-3565

A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowin…

Fix: 4.3.2 / 5.1.1+
Fix from $1,600 2021-06-04
Openshift Service Mesh HIGH 8.6
CVE-2020-1764

A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker co…

Fix: 1.15.1+
Fix from $1,950 2020-03-26
Keycloak CRITICAL 9.1
CVE-2019-14837

A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name …

Fix: 8.0.0+
Fix from $2,300 2020-01-07
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Openstack HIGH 8.8
CVE-2018-10898

A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Open…

Fix: 8.0.2-40+
Fix from $1,950 2018-07-30
Enterprise Linux Desktop HIGH 7.5
CVE-2017-7537

It was found that a mock CMC authentication plugin with a hardcoded secret was accidentally enabled by default in the pki-core package before 10.6.4.…

Fix: 10.6.4+
Fix from $1,950 2018-07-26
Enterprise Linux Server CRITICAL 9.8
CVE-2012-3503

The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default in…

Fix: after 1.0
Fix from $2,300 2012-08-25
Satellite CRITICAL 9.1
CVE-2008-2369

manzier.pxt in Red Hat Network Satellite Server before 5.1.1 has a hard-coded authentication key, which allows remote attackers to connect to the ser…

Fix: 5.1.1+
Fix from $2,300 2008-08-14