Vulnerability index

Browse CVEs

813 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2021-20252 A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges i… 3scale Api Management Mitigation only Fix from $1,6002021-02-23 MEDIUM 5.3 CVE-2021-20256 A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts perm… Satellite Mitigation only Fix from $1,6002021-02-23 HIGH 7.5 CVE-2020-27782 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings… Jboss Fuse Mitigation only Fix from $1,9502021-02-23 HIGH 7.3 CVE-2020-14359 A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gateke… Louketo Proxy Mitigation only Fix from $1,9502021-02-23 MEDIUM 6.1 CVE-2020-1723 A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver… Mobile Application Platform Mitigation only Fix from $1,6002021-01-28 MEDIUM 5.9 CVE-2020-25657 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the t… Virtualization Mitigation only Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2020-25680 A flaw was found in JBCS httpd in version 2.4.37 SP3, where it uses a back-end worker SSL certificate with the keystore file's ID is 'unknown'. The v… Jboss Core Services Httpd Mitigation only Fix from $1,6002021-01-07 MEDIUM 5.9 CVE-2020-27822 A flaw was found in Wildfly affecting versions 19.0.0.Final, 19.1.0.Final, 20.0.0.Final, 20.0.1.Final, and 21.0.0.Final. When an application uses the… Wildfly Mitigation only Fix from $1,6002020-12-08 MEDIUM 6.5 CVE-2020-25655 An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created f… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002020-11-09 HIGH 8.8 CVE-2020-25661 A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. … Enterprise Linux Mitigation only Fix from $1,9502020-11-05 MEDIUM 6.5 CVE-2020-25662 A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of s… Enterprise Linux Mitigation only Fix from $1,6002020-11-05 MEDIUM 5.5 CVE-2020-25635 A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. File… Ansible Mitigation only Fix from $1,6002020-10-05 HIGH 7.1 CVE-2020-25636 A flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are written d… Ansible Mitigation only Fix from $1,9502020-10-05 MEDIUM 5.3 CVE-2020-1710 The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400. Jboss Data Grid Mitigation only Fix from $1,6002020-09-16 MEDIUM 6.0 CVE-2020-10759 A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, a signatur… Enterprise Linux No fix yet Fix from $1,6002020-09-15 HIGH 7.1 CVE-2020-14296 Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker co… Cloudforms Management Engine Mitigation only Fix from $1,9502020-08-11 MEDIUM 6.3 CVE-2020-10780 Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with E… Cloudforms Management Engine Mitigation only Fix from $1,6002020-08-11 HIGH 8.3 CVE-2020-10783 Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricte… Cloudforms Mitigation only Fix from $1,9502020-08-11 MEDIUM 6.5 CVE-2020-10779 Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege ch… Cloudforms Mitigation only Fix from $1,6002020-08-11 MEDIUM 6.0 CVE-2020-10778 In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields sinc… Cloudforms Mitigation only Fix from $1,6002020-08-11 MEDIUM 5.4 CVE-2020-10777 A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS… Cloudforms Mitigation only Fix from $1,6002020-08-11 CRITICAL 9.9 CVE-2020-10731 A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw cause… Openstack Platform Mitigation only Fix from $2,3002020-07-31 HIGH 8.8 CVE-2020-14334 A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files. These cache credentials could help attacker to gain com… Satellite Mitigation only Fix from $1,9502020-07-31 MEDIUM 5.8 CVE-2020-14337 A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, rem… Ansible Tower Mitigation only Fix from $1,6002020-07-31 MEDIUM 6.5 CVE-2020-14307 A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never … Amq Mitigation only Fix from $1,6002020-07-24 MEDIUM 6.1 CVE-2019-3865 A vulnerability was found in quay-2, where a stored XSS vulnerability has been found in the super user function of quay. Attackers are able to use th… Quay Mitigation only Fix from $1,6002020-06-22 HIGH 7.2 CVE-2019-14894 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution throu… Cloudforms Management Engine Mitigation only Fix from $1,9502020-06-22 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 MEDIUM 6.6 CVE-2020-10706 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allow… Openshift Container Platform Mitigation only Fix from $1,6002020-05-12 MEDIUM 5.9 CVE-2020-1741 A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during … Openshift Container Platform Mitigation only Fix from $1,6002020-04-24