Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux Server HIGH 7.5
CVE-2022-2738

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,950 2022-09-01
Openstack Platform MEDIUM 6.6
CVE-2022-2447

A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be rev…

No fix yet
Fix from $1,600 2022-09-01
Advanced Cluster Management For Kubernetes MEDIUM 6.5
CVE-2022-2238

A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets pa…

Mitigation only
Fix from $1,600 2022-09-01
Openshift MEDIUM 6.5
CVE-2022-2403

A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the …

Patch available
Fix from $1,600 2022-09-01
Openshift Container Platform MEDIUM 6.3
CVE-2022-1677

In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of th…

Patch available
Fix from $1,600 2022-09-01
Enterprise Linux Server MEDIUM 5.3
CVE-2022-2739

The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t…

Mitigation only
Fix from $1,600 2022-09-01
Ansible Automation Platform MEDIUM 6.5
CVE-2022-1632

An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv…

Mitigation only
Fix from $1,600 2022-09-01
Jboss Data Grid HIGH 8.8
CVE-2022-1271

An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a…

Fix: 1.12 / 5.2.5+
Fix from $1,950 2022-08-31
Build Of Quarkus HIGH 7.5
CVE-2022-1259

A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of servic…

Fix: after 2.2.17
Fix from $1,950 2022-08-31
Openshift Application Runtimes HIGH 7.5
CVE-2022-1319

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set ev…

Fix: 2.2.17+
Fix from $1,950 2022-08-31
Enterprise Linux HIGH 7.5
CVE-2022-0934

A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dns…

Fix: 2.87+
Fix from $1,950 2022-08-29
Enterprise Linux MEDIUM 5.5
CVE-2022-0852

There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow una…

Fix: 0.26+
Fix from $1,600 2022-08-29
Enterprise Linux HIGH 7.8
CVE-2022-0358

A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local…

Fix: 6.2.0-7+
Fix from $1,950 2022-08-29
Openshift Container Platform MEDIUM 6.5
CVE-2022-0669

A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_IN…

Fix: 22.03+
Fix from $1,600 2022-08-29
Enterprise Linux MEDIUM 5.5
CVE-2022-0851

There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription…

No fix yet
Fix from $1,600 2022-08-29
Enterprise Linux MEDIUM 6.7
CVE-2022-34301

A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot pro…

Fix: 2022-06-01+
Fix from $1,600 2022-08-26
Enterprise Linux MEDIUM 6.7
CVE-2022-34302

A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot prote…

Fix: 2022-06-01+
Fix from $1,600 2022-08-26
Enterprise Linux MEDIUM 6.7
CVE-2022-34303

A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In …

Fix: 2022-06-01+
Fix from $1,600 2022-08-26
Integration Camel K HIGH 7.5
CVE-2022-0084

A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. …

Fix: 3.8.7+
Fix from $1,950 2022-08-26
Enterprise Linux MEDIUM 5.5
CVE-2022-0175

A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed mem…

Patch available
Fix from $1,600 2022-08-26
Keycloak MEDIUM 5.4
CVE-2022-0225

A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t…

No fix yet
Fix from $1,600 2022-08-26
Keycloak HIGH 7.5
CVE-2021-3632

A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered…

Fix: 7.4.9 / 15.1.0+
Fix from $1,950 2022-08-26
Openshift Serverless HIGH 7.5
CVE-2021-3703

It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Se…

Fix: 1.17.0+
Fix from $1,950 2022-08-26
Jboss Enterprise Application Platform HIGH 7.5
CVE-2021-3859

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carr…

Fix: 2.2.15+
Fix from $1,950 2022-08-26
Keycloak MEDIUM 5.3
CVE-2021-3754

A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus…

Mitigation only
Fix from $1,600 2022-08-26
Satellite HIGH 8.1
CVE-2021-3414

A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage othe…

Mitigation only
Fix from $1,950 2022-08-26
Enterprise Linux MEDIUM 6.7
CVE-2021-35939

It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to …

Fix: 4.18+
Fix from $1,600 2022-08-26
Ansible Automation Platform Early Access HIGH 8.8
CVE-2021-4112

A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the p…

Mitigation only
Fix from $1,950 2022-08-25
Ceph Storage MEDIUM 6.5
CVE-2021-3979

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo…

Patch available
Fix from $1,600 2022-08-25
Enterprise Linux MEDIUM 6.4
CVE-2021-35937

A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response …

Fix: 4.18.0+
Fix from $1,600 2022-08-25