Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2026-18572 Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18203 A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 8.8 CVE-2026-59851 A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos princ… Hardened Images No fix yet Fix from $1,9502026-07-21 HIGH 8.1 CVE-2026-3009 A security flaw in the IdentityBrokerService.performLogin endpoint of Keycloak allows authentication to proceed using an Identity Provider (IdP) even… Build Of Keycloak Mitigation only Fix from $1,9502026-03-05 MEDIUM 6.5 CVE-2025-9572 n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, … Satellite 3.16.2+ Fix from $1,6002026-02-27 HIGH 7.5 CVE-2024-10295 A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A mal… 3scale Api Management Mitigation only Fix from $1,9502024-10-24 HIGH 7.5 CVE-2022-3248 A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the bo… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-10-05 HIGH 8.1 CVE-2023-1832 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of… Satellite 4.3.7-3+ Fix from $1,9502023-10-04 HIGH 8.1 CVE-2023-4853 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti… Build Of Optaplanner 1.10.2 / 2.13.8+ Fix from $1,9502023-09-20 HIGH 7.8 CVE-2023-3899 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red… Subscription Manager 1.28.39 / 1.29.37+ Fix from $1,9502023-08-23 HIGH 7.8 CVE-2023-3027 The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-06-05 HIGH 7.1 CVE-2022-2989 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data … Openshift Container Platform Patch available Fix from $1,9502022-09-13 HIGH 7.1 CVE-2022-2990 An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data… Openshift Container Platform 1.27.1+ Fix from $1,9502022-09-13 HIGH 8.1 CVE-2022-23451 An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, mo… Openstack Platform 14.0.0+ Fix from $1,9502022-09-06 CRITICAL 9.1 CVE-2022-0670 A flaw was found in Openstack manilla owning a Ceph File system "share", which enables the owner to read/write any manilla share or entire file syste… Ceph Storage 5.2 / 15.2.17+ Fix from $2,3002022-07-25 MEDIUM 6.5 CVE-2022-1706 A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issu… Ignition 2.14.0+ Fix from $1,6002022-05-17 MEDIUM 5.3 CVE-2022-0866 This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a… Jboss Enterprise Application Platform 26.1.1+ Fix from $1,6002022-05-10 MEDIUM 6.5 CVE-2022-1466 Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was po… Keycloak 17.0.1+ Fix from $1,6002022-04-26 HIGH 8.8 CVE-2021-4133 A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default … Keycloak 15.1.1+ Fix from $1,9502022-01-25 HIGH 8.1 CVE-2021-20179 A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and … Certificate System 10.5.0 / 10.8.0+ Fix from $1,9502021-03-15 HIGH 7.0 CVE-2021-20188 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw c… Openshift Container Platform 1.7.0+ Fix from $1,9502021-02-11 MEDIUM 5.4 CVE-2020-1725 A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycl… Keycloak 13.0.0+ Fix from $1,6002021-01-28 MEDIUM 6.5 CVE-2020-25655 An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002020-11-09 HIGH 8.8 CVE-2019-14843 A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a mal… Single Sign On Patch available Fix from $1,9502020-01-07 MEDIUM 6.5 CVE-2014-0169 In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002020-01-02 MEDIUM 6.5 CVE-2015-1780 oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center Ovirt Engine Mitigation only Fix from $1,6002019-11-22 CRITICAL 9.1 CVE-2010-2548 IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. Icedtea6 1.7.4+ Fix from $2,3002019-10-31 HIGH 7.5 CVE-2019-14832 A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authent… Keycloak 7.0.1+ Fix from $1,9502019-10-15 CRITICAL 9.8 CVE-2019-14813EPSS 11% A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, en… Openshift Container Platform Patch available Fix from $2,3002019-09-06 HIGH 7.8 CVE-2019-14811 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls… Openshift Container Platform 9.50+ Fix from $1,9502019-09-03