Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Build Of Keycloak MEDIUM 6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p…

No fix yet
Fix from $1,600 2026-07-31
Hardened Images HIGH 8.8
CVE-2026-59851

A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ…

No fix yet
Fix from $1,950 2026-07-21
Build Of Keycloak HIGH 8.1
CVE-2026-3009

A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even…

Mitigation only
Fix from $1,950 2026-03-05
Satellite MEDIUM 6.5
CVE-2025-9572

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, …

Fix: 3.16.2+
Fix from $1,600 2026-02-27
3scale Api Management HIGH 7.5
CVE-2024-10295

A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal…

Mitigation only
Fix from $1,950 2024-10-24
Advanced Cluster Management For Kubernetes HIGH 7.5
CVE-2022-3248

A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo…

Mitigation only
Fix from $1,950 2023-10-05
Satellite HIGH 8.1
CVE-2023-1832

An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of…

Fix: 4.3.7-3+
Fix from $1,950 2023-10-04
Build Of Optaplanner HIGH 8.1
CVE-2023-4853

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…

Fix: 1.10.2 / 2.13.8+
Fix from $1,950 2023-09-20
Subscription Manager HIGH 7.8
CVE-2023-3899

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…

Fix: 1.28.39 / 1.29.37+
Fix from $1,950 2023-08-23
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Openshift Container Platform HIGH 7.1
CVE-2022-2989

An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data …

Patch available
Fix from $1,950 2022-09-13
Openshift Container Platform HIGH 7.1
CVE-2022-2990

An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data…

Fix: 1.27.1+
Fix from $1,950 2022-09-13
Openstack Platform HIGH 8.1
CVE-2022-23451

An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo…

Fix: 14.0.0+
Fix from $1,950 2022-09-06
Ceph Storage CRITICAL 9.1
CVE-2022-0670

A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste…

Fix: 5.2 / 15.2.17+
Fix from $2,300 2022-07-25
Ignition MEDIUM 6.5
CVE-2022-1706

A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu…

Fix: 2.14.0+
Fix from $1,600 2022-05-17
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2022-0866

This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a…

Fix: 26.1.1+
Fix from $1,600 2022-05-10
Keycloak MEDIUM 6.5
CVE-2022-1466

Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po…

Fix: 17.0.1+
Fix from $1,600 2022-04-26
Keycloak HIGH 8.8
CVE-2021-4133

A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default …

Fix: 15.1.1+
Fix from $1,950 2022-01-25
Certificate System HIGH 8.1
CVE-2021-20179

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …

Fix: 10.5.0 / 10.8.0+
Fix from $1,950 2021-03-15
Openshift Container Platform HIGH 7.0
CVE-2021-20188

A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c…

Fix: 1.7.0+
Fix from $1,950 2021-02-11
Keycloak MEDIUM 5.4
CVE-2020-1725

A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl…

Fix: 13.0.0+
Fix from $1,600 2021-01-28
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2020-25655

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…

Mitigation only
Fix from $1,600 2020-11-09
Single Sign On HIGH 8.8
CVE-2019-14843

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal…

Patch available
Fix from $1,950 2020-01-07
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2014-0169

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…

Mitigation only
Fix from $1,600 2020-01-02
Ovirt Engine MEDIUM 6.5
CVE-2015-1780

oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center

Mitigation only
Fix from $1,600 2019-11-22
Icedtea6 CRITICAL 9.1
CVE-2010-2548

IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

Fix: 1.7.4+
Fix from $2,300 2019-10-31
Keycloak HIGH 7.5
CVE-2019-14832

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent…

Fix: 7.0.1+
Fix from $1,950 2019-10-15
Openshift Container Platform CRITICAL 9.8
CVE-2019-14813EPSS 11%

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en…

Patch available
Fix from $2,300 2019-09-06
Openshift Container Platform HIGH 7.8
CVE-2019-14811

A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls…

Fix: 9.50+
Fix from $1,950 2019-09-03