Vulnerability index

Browse CVEs

815 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2022-3205 Cross site scripting in automation controller UI in Red Hat Ansible Automation Platform 1.2 and 2.0 where the project name is susceptible to XSS inje… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-13 HIGH 7.5 CVE-2022-2738 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t… Enterprise Linux Server Mitigation only Fix from $1,9502022-09-01 MEDIUM 6.6 CVE-2022-2447 A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be rev… Openstack Platform No fix yet Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-2238 A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets pa… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002022-09-01 MEDIUM 5.3 CVE-2022-2739 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t… Enterprise Linux Server Mitigation only Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-1632 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-01 MEDIUM 5.5 CVE-2022-0851 There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription… Enterprise Linux No fix yet Fix from $1,6002022-08-29 MEDIUM 5.4 CVE-2022-0225 A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t… Keycloak No fix yet Fix from $1,6002022-08-26 MEDIUM 5.3 CVE-2021-3754 A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus… Keycloak Mitigation only Fix from $1,6002022-08-26 HIGH 8.1 CVE-2021-3414 A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage othe… Satellite Mitigation only Fix from $1,9502022-08-26 HIGH 8.8 CVE-2021-4112 A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the p… Ansible Automation Platform Early Access Mitigation only Fix from $1,9502022-08-25 MEDIUM 5.4 CVE-2020-35509 A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because… Keycloak Mitigation only Fix from $1,6002022-08-23 CRITICAL 9.8 CVE-2021-3586 A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo… Openshift Service Mesh Mitigation only Fix from $2,3002022-08-22 HIGH 8.8 CVE-2021-3590 A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output… Satellite Mitigation only Fix from $1,9502022-08-22 MEDIUM 5.4 CVE-2021-3442 A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s… Openshift Api Management Mitigation only Fix from $1,6002022-08-22 MEDIUM 6.5 CVE-2022-2568 A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions… Ansible Automation Platform No fix yet Fix from $1,6002022-08-18 MEDIUM 5.6 CVE-2020-14379 A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info… Jboss A Mq Mitigation only Fix from $1,6002022-08-16 HIGH 7.2 CVE-2022-2668 An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature i… Keycloak Mitigation only Fix from $1,9502022-08-05 MEDIUM 6.5 CVE-2022-1655 An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without … Openstack Mitigation only Fix from $1,6002022-07-22 MEDIUM 6.5 CVE-2022-2211 A vulnerability was found in libguestfs. This issue occurs while calculating the greatest possible number of matching keys in the get_keys() function… Enterprise Linux No fix yet Fix from $1,6002022-07-12 CRITICAL 9.1 CVE-2014-8164 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat Cloud… Cloudforms Management Engine Mitigation only Fix from $2,3002022-07-06 HIGH 7.0 CVE-2021-3697 A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to … Developer Tools Mitigation only Fix from $1,9502022-07-06 HIGH 7.5 CVE-2014-3648 The simplepush server iterates through the application installations and pushes a notification to the server provided by deviceToken. But this is use… Jboss Aerogear Mitigation only Fix from $1,9502022-07-01 MEDIUM 5.4 CVE-2014-3650 Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could us… Jboss Aerogear Mitigation only Fix from $1,6002022-07-01 MEDIUM 5.5 CVE-2014-0068 It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. Openshift Origin Node Util Mitigation only Fix from $1,6002022-06-30 HIGH 8.8 CVE-2022-1833 A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where th… Amq Broker Mitigation only Fix from $1,9502022-06-21 HIGH 8.2 CVE-2022-1665 A set of pre-production kernel packages of Red Hat Enterprise Linux for IBM Power architecture can be booted by the grub in Secure Boot mode even tho… Enterprise Linux Mitigation only Fix from $1,9502022-06-21 MEDIUM 5.5 CVE-2021-3681 A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly ex… Ansible Automation Platform Mitigation only Fix from $1,6002022-04-18 HIGH 7.8 CVE-2022-1304 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code executi… Enterprise Linux Mitigation only Fix from $1,9502022-04-14 HIGH 7.5 CVE-2021-4047 The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only aff… Openshift Mitigation only Fix from $1,9502022-04-11