Vulnerability index

Browse CVEs

817 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-4237 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the stand… Ansible Automation Platform Mitigation only Fix from $1,9502023-10-04 MEDIUM 6.3 CVE-2023-4380 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T… Ansible Automation Platform Mitigation only Fix from $1,6002023-10-04 HIGH 7.4 CVE-2023-4586 A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS,… Data Grid Mitigation only Fix from $1,9502023-10-04 HIGH 7.1 CVE-2023-2422 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the clien… Keycloak Mitigation only Fix from $1,9502023-10-04 MEDIUM 5.5 CVE-2023-4066 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecur… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 MEDIUM 5.5 CVE-2023-4065 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Opera… Jboss A Mq Mitigation only Fix from $1,6002023-09-27 MEDIUM 6.1 CVE-2022-4137 A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a m… Keycloak Mitigation only Fix from $1,6002023-09-25 MEDIUM 5.5 CVE-2023-1633 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce… Openstack Platform Mitigation only Fix from $1,6002023-09-24 MEDIUM 5.0 CVE-2023-1636 A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configura… Openstack Platform Mitigation only Fix from $1,6002023-09-24 CRITICAL 9.8 CVE-2022-4039 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This … Single Sign On Mitigation only Fix from $2,3002023-09-22 CRITICAL 9.1 CVE-2022-3874 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm… Satellite Mitigation only Fix from $2,3002023-09-22 HIGH 7.5 CVE-2022-3596 An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discoveri… Openstack Platform Mitigation only Fix from $1,9502023-09-20 MEDIUM 6.5 CVE-2023-4527 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode v… Codeready Linux Builder Eus No fix yet Fix from $1,6002023-09-18 MEDIUM 5.9 CVE-2023-4806 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an … Codeready Linux Builder Eus Mitigation only Fix from $1,6002023-09-18 HIGH 7.5 CVE-2022-3261 A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading … Openstack Platform Mitigation only Fix from $1,9502023-09-15 HIGH 7.5 CVE-2023-0813 A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic… Network Observability Mitigation only Fix from $1,9502023-09-15 MEDIUM 6.5 CVE-2023-4959 A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i… Quay Mitigation only Fix from $1,6002023-09-15 HIGH 7.5 CVE-2023-1108 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh… Build Of Quarkus Mitigation only Fix from $1,9502023-09-14 HIGH 8.2 CVE-2023-2680 This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 … Enterprise Linux Mitigation only Fix from $1,9502023-09-13 HIGH 8.8 CVE-2023-4918 A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa… Keycloak Mitigation only Fix from $1,9502023-09-12 MEDIUM 5.4 CVE-2023-0119 A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As… Satellite Mitigation only Fix from $1,6002023-09-12 HIGH 8.8 CVE-2022-1415 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a… Decision Manager Mitigation only Fix from $1,9502023-09-11 MEDIUM 5.5 CVE-2023-4042 A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th… Codeready Linux Builder No fix yet Fix from $1,6002023-08-23 MEDIUM 6.5 CVE-2023-4456 A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a toke… Openshift Logging Mitigation only Fix from $1,6002023-08-21 MEDIUM 6.5 CVE-2023-3637 An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr… Openstack Platform Mitigation only Fix from $1,6002023-07-25 MEDIUM 5.3 CVE-2023-3750 A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and de… Libvirt Mitigation only Fix from $1,6002023-07-24 MEDIUM 5.4 CVE-2023-3384 A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex … Quay Mitigation only Fix from $1,6002023-07-24 HIGH 7.5 CVE-2023-3089 A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the crypt… Openshift Container Platform Mitigation only Fix from $1,9502023-07-05 MEDIUM 6.5 CVE-2023-2253 A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records retu… Openshift Api For Data Protection Mitigation only Fix from $1,6002023-06-06 HIGH 7.8 CVE-2023-3027 The grc-policy-propagator allows security escalation within the cluster. The propagator allows policies which contain some dynamically obtained value… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-06-05