Vulnerability index

Browse CVEs

815 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ansible Automation Platform MEDIUM 6.1
CVE-2022-3205

Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje…

Mitigation only
Fix from $1,600 2022-09-13
Enterprise Linux Server HIGH 7.5
CVE-2022-2738

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,950 2022-09-01
Openstack Platform MEDIUM 6.6
CVE-2022-2447

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be rev…

No fix yet
Fix from $1,600 2022-09-01
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2022-2238

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets pa…

Mitigation only
Fix from $1,600 2022-09-01
Enterprise Linux Server MEDIUM 5.3
CVE-2022-2739

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,600 2022-09-01
Ansible Automation Platform MEDIUM 6.5
CVE-2022-1632

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv…

Mitigation only
Fix from $1,600 2022-09-01
Enterprise Linux MEDIUM 5.5
CVE-2022-0851

There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription…

No fix yet
Fix from $1,600 2022-08-29
Keycloak MEDIUM 5.4
CVE-2022-0225

A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t…

No fix yet
Fix from $1,600 2022-08-26
Keycloak MEDIUM 5.3
CVE-2021-3754

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus…

Mitigation only
Fix from $1,600 2022-08-26
Satellite HIGH 8.1
CVE-2021-3414

A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage othe…

Mitigation only
Fix from $1,950 2022-08-26
Ansible Automation Platform Early Access HIGH 8.8
CVE-2021-4112

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the p…

Mitigation only
Fix from $1,950 2022-08-25
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Openshift Service Mesh CRITICAL 9.8
CVE-2021-3586

A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo…

Mitigation only
Fix from $2,300 2022-08-22
Satellite HIGH 8.8
CVE-2021-3590

A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…

Mitigation only
Fix from $1,950 2022-08-22
Openshift Api Management MEDIUM 5.4
CVE-2021-3442

A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s…

Mitigation only
Fix from $1,600 2022-08-22
Ansible Automation Platform MEDIUM 6.5
CVE-2022-2568

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions…

No fix yet
Fix from $1,600 2022-08-18
Jboss A Mq MEDIUM 5.6
CVE-2020-14379

A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info…

Mitigation only
Fix from $1,600 2022-08-16
Keycloak HIGH 7.2
CVE-2022-2668

An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature i…

Mitigation only
Fix from $1,950 2022-08-05
Openstack MEDIUM 6.5
CVE-2022-1655

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without …

Mitigation only
Fix from $1,600 2022-07-22
Enterprise Linux MEDIUM 6.5
CVE-2022-2211

A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function…

No fix yet
Fix from $1,600 2022-07-12
Cloudforms Management Engine CRITICAL 9.1
CVE-2014-8164

A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud…

Mitigation only
Fix from $2,300 2022-07-06
Developer Tools HIGH 7.0
CVE-2021-3697

A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to …

Mitigation only
Fix from $1,950 2022-07-06
Jboss Aerogear HIGH 7.5
CVE-2014-3648

The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use…

Mitigation only
Fix from $1,950 2022-07-01
Jboss Aerogear MEDIUM 5.4
CVE-2014-3650

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us…

Mitigation only
Fix from $1,600 2022-07-01
Openshift Origin Node Util MEDIUM 5.5
CVE-2014-0068

It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.

Mitigation only
Fix from $1,600 2022-06-30
Amq Broker HIGH 8.8
CVE-2022-1833

A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th…

Mitigation only
Fix from $1,950 2022-06-21
Enterprise Linux HIGH 8.2
CVE-2022-1665

A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even tho…

Mitigation only
Fix from $1,950 2022-06-21
Ansible Automation Platform MEDIUM 5.5
CVE-2021-3681

A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex…

Mitigation only
Fix from $1,600 2022-04-18
Enterprise Linux HIGH 7.8
CVE-2022-1304

An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi…

Mitigation only
Fix from $1,950 2022-04-14
Openshift HIGH 7.5
CVE-2021-4047

The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff…

Mitigation only
Fix from $1,950 2022-04-11