Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.5
CVE-2023-5156

A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application …

Fix: 2.39+
Fix from $1,950 2023-09-25
Openstack Platform MEDIUM 5.5
CVE-2023-1633

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce…

Mitigation only
Fix from $1,600 2023-09-24
Openstack Platform MEDIUM 5.0
CVE-2023-1625

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reve…

Patch available
Fix from $1,600 2023-09-24
Openstack Platform MEDIUM 5.0
CVE-2023-1636

A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configura…

Mitigation only
Fix from $1,600 2023-09-24
Single Sign On CRITICAL 9.8
CVE-2022-4039

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This …

Mitigation only
Fix from $2,300 2023-09-22
Satellite CRITICAL 9.1
CVE-2022-3874

A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…

Mitigation only
Fix from $2,300 2023-09-22
Openstack Platform HIGH 7.5
CVE-2022-3596

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discoveri…

Mitigation only
Fix from $1,950 2023-09-20
Keycloak MEDIUM 6.8
CVE-2022-3916

A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not clear…

Fix: 20.0.2+
Fix from $1,600 2023-09-20
Satellite CRITICAL 9.1
CVE-2023-0118

An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …

Fix: 6.13.3+
Fix from $2,300 2023-09-20
Satellite CRITICAL 9.1
CVE-2023-0462

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…

Fix: 3.8.0+
Fix from $2,300 2023-09-20
Build Of Optaplanner HIGH 8.1
CVE-2023-4853

A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti…

Fix: 1.10.2 / 2.13.8+
Fix from $1,950 2023-09-20
Codeready Linux Builder Eus MEDIUM 6.5
CVE-2023-4527

A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode v…

No fix yet
Fix from $1,600 2023-09-18
Codeready Linux Builder Eus MEDIUM 5.9
CVE-2023-4806

A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an …

Mitigation only
Fix from $1,600 2023-09-18
Openshift Data Science CRITICAL 9.8
CVE-2023-0923

A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making …

Fix: 1.22.1-3+
Fix from $2,300 2023-09-15
Openstack Platform HIGH 7.5
CVE-2022-3261

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading …

Mitigation only
Fix from $1,950 2023-09-15
Network Observability HIGH 7.5
CVE-2023-0813

A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic…

Mitigation only
Fix from $1,950 2023-09-15
Quay MEDIUM 6.5
CVE-2023-4959

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i…

Mitigation only
Fix from $1,600 2023-09-15
Build Of Quarkus HIGH 7.5
CVE-2023-1108

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh…

Mitigation only
Fix from $1,950 2023-09-14
Enterprise Linux MEDIUM 5.6
CVE-2023-3301

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci fr…

Fix: after 8.0.3
Fix from $1,600 2023-09-13
Enterprise Linux HIGH 8.2
CVE-2023-2680

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 …

Mitigation only
Fix from $1,950 2023-09-13
Enterprise Linux MEDIUM 6.5
CVE-2023-3255

A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when in…

Fix: after 8.0.3
Fix from $1,600 2023-09-13
Enterprise Linux MEDIUM 5.9
CVE-2023-4813

A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application…

Patch available
Fix from $1,600 2023-09-12
Keycloak HIGH 8.8
CVE-2023-4918

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa…

Mitigation only
Fix from $1,950 2023-09-12
Satellite MEDIUM 5.4
CVE-2023-0119

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As…

Mitigation only
Fix from $1,600 2023-09-12
Decision Manager HIGH 8.8
CVE-2022-1415

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a…

Mitigation only
Fix from $1,950 2023-09-11
Enterprise Linux MEDIUM 6.5
CVE-2023-38201

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo…

Patch available
Fix from $1,600 2023-08-25
Codeready Linux Builder MEDIUM 5.5
CVE-2023-4042

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th…

No fix yet
Fix from $1,600 2023-08-23
Subscription Manager HIGH 7.8
CVE-2023-3899

A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red…

Fix: 1.28.39 / 1.29.37+
Fix from $1,950 2023-08-23
Openshift Logging MEDIUM 6.5
CVE-2023-4456

A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a toke…

Mitigation only
Fix from $1,600 2023-08-21
Enterprise Linux MEDIUM 6.5
CVE-2022-40982

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may al…

Fix: 20230808+
Fix from $1,600 2023-08-11