Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

3scale Api Management MEDIUM 6.5
CVE-2021-20252

A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i…

Mitigation only
Fix from $1,600 2021-02-23
Satellite MEDIUM 5.3
CVE-2021-20256

A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm…

Mitigation only
Fix from $1,600 2021-02-23
Jboss Fuse HIGH 7.5
CVE-2020-27782

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings…

Mitigation only
Fix from $1,950 2021-02-23
Louketo Proxy HIGH 7.3
CVE-2020-14359

A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gateke…

Mitigation only
Fix from $1,950 2021-02-23
Mobile Application Platform MEDIUM 6.1
CVE-2020-1723

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver…

Mitigation only
Fix from $1,600 2021-01-28
Virtualization MEDIUM 5.9
CVE-2020-25657

A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the t…

Mitigation only
Fix from $1,600 2021-01-12
Jboss Core Services Httpd MEDIUM 5.4
CVE-2020-25680

A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v…

Mitigation only
Fix from $1,600 2021-01-07
Wildfly MEDIUM 5.9
CVE-2020-27822

A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the…

Mitigation only
Fix from $1,600 2020-12-08
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2020-25655

An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f…

Mitigation only
Fix from $1,600 2020-11-09
Enterprise Linux HIGH 8.8
CVE-2020-25661

A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. …

Mitigation only
Fix from $1,950 2020-11-05
Enterprise Linux MEDIUM 6.5
CVE-2020-25662

A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s…

Mitigation only
Fix from $1,600 2020-11-05
Ansible MEDIUM 5.5
CVE-2020-25635

A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. File…

Mitigation only
Fix from $1,600 2020-10-05
Ansible HIGH 7.1
CVE-2020-25636

A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written d…

Mitigation only
Fix from $1,950 2020-10-05
Jboss Data Grid MEDIUM 5.3
CVE-2020-1710

The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.

Mitigation only
Fix from $1,600 2020-09-16
Enterprise Linux MEDIUM 6.0
CVE-2020-10759

A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur…

No fix yet
Fix from $1,600 2020-09-15
Cloudforms Management Engine HIGH 7.1
CVE-2020-14296

Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co…

Mitigation only
Fix from $1,950 2020-08-11
Cloudforms Management Engine MEDIUM 6.3
CVE-2020-10780

Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with E…

Mitigation only
Fix from $1,600 2020-08-11
Cloudforms HIGH 8.3
CVE-2020-10783

Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricte…

Mitigation only
Fix from $1,950 2020-08-11
Cloudforms MEDIUM 6.5
CVE-2020-10779

Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch…

Mitigation only
Fix from $1,600 2020-08-11
Cloudforms MEDIUM 6.0
CVE-2020-10778

In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields sinc…

Mitigation only
Fix from $1,600 2020-08-11
Cloudforms MEDIUM 5.4
CVE-2020-10777

A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS…

Mitigation only
Fix from $1,600 2020-08-11
Openstack Platform CRITICAL 9.9
CVE-2020-10731

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause…

Mitigation only
Fix from $2,300 2020-07-31
Satellite HIGH 8.8
CVE-2020-14334

A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com…

Mitigation only
Fix from $1,950 2020-07-31
Ansible Tower MEDIUM 5.8
CVE-2020-14337

A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, rem…

Mitigation only
Fix from $1,600 2020-07-31
Amq MEDIUM 6.5
CVE-2020-14307

A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never …

Mitigation only
Fix from $1,600 2020-07-24
Quay MEDIUM 6.1
CVE-2019-3865

A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use th…

Mitigation only
Fix from $1,600 2020-06-22
Cloudforms Management Engine HIGH 7.2
CVE-2019-14894

A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu…

Mitigation only
Fix from $1,950 2020-06-22
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Openshift Container Platform MEDIUM 6.6
CVE-2020-10706

A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allow…

Mitigation only
Fix from $1,600 2020-05-12
Openshift Container Platform MEDIUM 5.9
CVE-2020-1741

A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during …

Mitigation only
Fix from $1,600 2020-04-24