Vulnerability index

Browse CVEs

815 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Data Grid HIGH 7.4
CVE-2023-4586

A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,…

Mitigation only
Fix from $1,950 2023-10-04
Keycloak HIGH 7.1
CVE-2023-2422

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien…

Mitigation only
Fix from $1,950 2023-10-04
Jboss A Mq MEDIUM 5.5
CVE-2023-4066

A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecur…

Mitigation only
Fix from $1,600 2023-09-27
Jboss A Mq MEDIUM 5.5
CVE-2023-4065

A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera…

Mitigation only
Fix from $1,600 2023-09-27
Keycloak MEDIUM 6.1
CVE-2022-4137

A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m…

Mitigation only
Fix from $1,600 2023-09-25
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24
Openstack Platform MEDIUM 5.0
CVE-2023-1636

A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configura…

Mitigation only
Fix from $1,600 2023-09-24
Single Sign On CRITICAL 9.8
CVE-2022-4039

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …

Mitigation only
Fix from $2,300 2023-09-22
Satellite CRITICAL 9.1
CVE-2022-3874

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…

Mitigation only
Fix from $2,300 2023-09-22
Openstack Platform HIGH 7.5
CVE-2022-3596

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discoveri…

Mitigation only
Fix from $1,950 2023-09-20
Codeready Linux Builder Eus MEDIUM 6.5
CVE-2023-4527

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode v…

No fix yet
Fix from $1,600 2023-09-18
Codeready Linux Builder Eus MEDIUM 5.9
CVE-2023-4806

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an …

Mitigation only
Fix from $1,600 2023-09-18
Openstack Platform HIGH 7.5
CVE-2022-3261

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading …

Mitigation only
Fix from $1,950 2023-09-15
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Quay MEDIUM 6.5
CVE-2023-4959

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i…

Mitigation only
Fix from $1,600 2023-09-15
Build Of Quarkus HIGH 7.5
CVE-2023-1108

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…

Mitigation only
Fix from $1,950 2023-09-14
Enterprise Linux HIGH 8.2
CVE-2023-2680

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 …

Mitigation only
Fix from $1,950 2023-09-13
Keycloak HIGH 8.8
CVE-2023-4918

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa…

Mitigation only
Fix from $1,950 2023-09-12
Satellite MEDIUM 5.4
CVE-2023-0119

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As…

Mitigation only
Fix from $1,600 2023-09-12
Decision Manager HIGH 8.8
CVE-2022-1415

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a…

Mitigation only
Fix from $1,950 2023-09-11
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4042

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th…

No fix yet
Fix from $1,600 2023-08-23
Openshift Logging MEDIUM 6.5
CVE-2023-4456

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a toke…

Mitigation only
Fix from $1,600 2023-08-21
Openstack Platform MEDIUM 6.5
CVE-2023-3637

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr…

Mitigation only
Fix from $1,600 2023-07-25
Libvirt MEDIUM 5.3
CVE-2023-3750

A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and de…

Mitigation only
Fix from $1,600 2023-07-24
Quay MEDIUM 5.4
CVE-2023-3384

A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex …

Mitigation only
Fix from $1,600 2023-07-24
Openshift Container Platform HIGH 7.5
CVE-2023-3089

A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the crypt…

Mitigation only
Fix from $1,950 2023-07-05
Openshift Api For Data Protection MEDIUM 6.5
CVE-2023-2253

A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retu…

Mitigation only
Fix from $1,600 2023-06-06
Advanced Cluster Management For Kubernetes HIGH 7.8
CVE-2023-3027

The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value…

Mitigation only
Fix from $1,950 2023-06-05
Build Of Quarkus MEDIUM 6.5
CVE-2023-1664

A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is…

Mitigation only
Fix from $1,600 2023-05-26
Enterprise Linux High Availability CRITICAL 9.8
CVE-2023-2319

It was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…

Mitigation only
Fix from $2,300 2023-05-17