JBoss KeyCloak: XSS in login-status-iframe.html
openstack-utils openstack-db has insecure password creation
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…
OpenShift cartridge allows remote URL retrieval
Katello has multiple XSS issues in various entities
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from …
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …
A DOM based cross-site scripting flaw was found in the JBoss Application Server 7 before 7.1.0 Beta 1 administration console. A remote attacker could…
Designate does not enforce the DNS protocol limit concerning record set sizes
redhat-upgrade-tool: Does not check GPG signatures when upgrading versions
oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure m…
cumin: At installation postgresql database user created without password
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
OpenShift: Install script has temporary file creation vulnerability which can result in arbitrary code execution
vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
CloudForms stores user passwords in recoverable format
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in …
cartridges/openshift-origin-cartridge-mongodb-2.2/info/bin/dump.sh in OpenShift does not properly create files in /tmp.
Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL cert…
A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525…
A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found …