Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ceph Storage HIGH 7.5
CVE-2020-1699

A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i…

Mitigation only
Fix from $1,950 2020-04-21
Openshift HIGH 7.0
CVE-2019-19351

An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container…

Mitigation only
Fix from $1,950 2020-03-18
Openshift HIGH 7.0
CVE-2019-19355

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co…

Mitigation only
Fix from $1,950 2020-03-18
Jboss Data Grid CRITICAL 9.1
CVE-2019-14887

A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An…

Mitigation only
Fix from $2,300 2020-03-16
Openshift Container Platform HIGH 7.0
CVE-2020-1706

It has been found that in openshift-enterprise version 3.11 and openshift-enterprise versions 4.1 up to, including 4.3, multiple containers modify th…

Mitigation only
Fix from $1,950 2020-03-09
Decision Manager MEDIUM 6.5
CVE-2019-14886

A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context…

Mitigation only
Fix from $1,600 2020-03-05
Enterprise Linux HIGH 8.8
CVE-2012-4512EPSS 12%

The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read mem…

No fix yet
Fix from $1,950 2020-02-08
Openshift Container Platform HIGH 7.0
CVE-2020-1708

It has been found in openshift-enterprise version 3.11 and all openshift-enterprise versions from 4.1 to, including 4.3, that multiple containers mod…

Mitigation only
Fix from $1,950 2020-02-07
Openshift Container Storage MEDIUM 6.5
CVE-2020-1700

A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making mult…

Mitigation only
Fix from $1,600 2020-02-07
Openshift CRITICAL 9.8
CVE-2013-2060EPSS 6%

The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a req…

No fix yet
Fix from $2,300 2020-01-28
Jboss Brms HIGH 7.5
CVE-2012-5626

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and…

Mitigation only
Fix from $1,950 2020-01-23
Enterprise Linux MEDIUM 6.5
CVE-2019-19339

It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel…

Mitigation only
Fix from $1,600 2020-01-17
Openshift Container Platform HIGH 8.8
CVE-2019-14819

A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to…

No fix yet
Fix from $1,950 2020-01-07
Openshift Container Platform MEDIUM 6.5
CVE-2019-14854

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…

No fix yet
Fix from $1,600 2020-01-07
Satellite MEDIUM 6.5
CVE-2014-3590

Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log …

Mitigation only
Fix from $1,600 2020-01-02
Subscription Asset Manager MEDIUM 6.1
CVE-2014-0183

Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering.

Mitigation only
Fix from $1,600 2020-01-02
Jboss Portal MEDIUM 5.9
CVE-2014-0245

It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, und…

Mitigation only
Fix from $1,600 2020-01-02
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2014-0169

In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could all…

Mitigation only
Fix from $1,600 2020-01-02
Quay MEDIUM 6.3
CVE-2019-10205

A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay …

Mitigation only
Fix from $1,600 2020-01-02
Openshift MEDIUM 6.5
CVE-2013-0196

A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection me…

No fix yet
Fix from $1,600 2019-12-30
Ceph Storage MEDIUM 6.5
CVE-2019-19337

A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse …

Mitigation only
Fix from $1,600 2019-12-23
Jboss Fuse MEDIUM 6.1
CVE-2016-1000229

swagger-ui has XSS in key names

Mitigation only
Fix from $1,600 2019-12-20
Jboss Application Server HIGH 7.8
CVE-2012-2312

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat …

Mitigation only
Fix from $1,950 2019-12-18
Edeploy CRITICAL 9.8
CVE-2014-3699

eDeploy has RCE via cPickle deserialization of untrusted data

No fix yet
Fix from $2,300 2019-12-15
Edeploy HIGH 8.1
CVE-2014-3701

eDeploy has tmp file race condition flaws

No fix yet
Fix from $1,950 2019-12-15
Cloudforms Management Engine MEDIUM 5.5
CVE-2014-3536

CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

Mitigation only
Fix from $1,600 2019-12-15
Satellite MEDIUM 5.5
CVE-2014-0241

rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable

Mitigation only
Fix from $1,600 2019-12-13
Openshift CRITICAL 9.8
CVE-2014-0175

mcollective has a default password set at install

Mitigation only
Fix from $2,300 2019-12-13
Openshift HIGH 8.8
CVE-2014-0163

Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.

Mitigation only
Fix from $1,950 2019-12-11
Subscription Asset Manager MEDIUM 6.5
CVE-2014-0026

katello-headpin is vulnerable to CSRF in REST API

No fix yet
Fix from $1,600 2019-12-11