Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Build Of Quarkus MEDIUM 6.1
CVE-2021-3914

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cro…

Fix: 2.7.5+
Fix from $1,600 2022-08-25
Enterprise Linux HIGH 7.8
CVE-2022-0135

An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially…

Fix: 0.10.0+
Fix from $1,950 2022-08-25
Openshift HIGH 8.1
CVE-2021-4125

It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J…

Fix: 4.6.52 / 4.7.40+
Fix from $1,950 2022-08-24
Ansible Runner HIGH 7.8
CVE-2021-4041

A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to pa…

Fix: 2.1.0+
Fix from $1,950 2022-08-24
Enterprise Linux HIGH 7.5
CVE-2021-4213

A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the se…

Fix: 4.9.3 / 5.1.0+
Fix from $1,950 2022-08-24
Fabric8 Kubernetes MEDIUM 6.7
CVE-2021-4178

A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure…

Fix: 5.0.3 / 5.1.2+
Fix from $1,600 2022-08-24
Enterprise Linux MEDIUM 6.5
CVE-2021-4209

A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause …

Fix: 3.7.3+
Fix from $1,600 2022-08-24
Enterprise Linux MEDIUM 6.0
CVE-2021-4158

A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the Q…

Fix: 7.0.0+
Fix from $1,600 2022-08-24
Amq Broker MEDIUM 5.3
CVE-2021-4040

A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. T…

Fix: 2.19.1 / 7.10.0+
Fix from $1,600 2022-08-24
Libvirt MEDIUM 6.5
CVE-2021-3975

A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads with…

Fix: 7.1.0+
Fix from $1,600 2022-08-23
Coreos Installer MEDIUM 5.5
CVE-2021-3917

A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw …

Fix: 0.10.0+
Fix from $1,600 2022-08-23
Enterprise Linux Fast Datapath HIGH 7.5
CVE-2021-3905

A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust av…

Fix: 2.17.0+
Fix from $1,950 2022-08-23
Keycloak MEDIUM 6.8
CVE-2021-3827

A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at…

Fix: 18.0.0+
Fix from $1,600 2022-08-23
Fuse HIGH 7.5
CVE-2021-3690

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cau…

Fix: 2.0.40 / 2.2.10+
Fix from $1,950 2022-08-23
Ansible Runner MEDIUM 6.6
CVE-2021-3701

A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all…

Patch available
Fix from $1,600 2022-08-23
Storage MEDIUM 6.5
CVE-2021-3670

MaxQueryDuration not honoured in Samba AD DC LDAP

Fix: 4.16.0+
Fix from $1,600 2022-08-23
Ansible Runner MEDIUM 6.3
CVE-2021-3702

A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute…

Patch available
Fix from $1,600 2022-08-23
Keycloak MEDIUM 5.4
CVE-2020-35509

A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because…

Mitigation only
Fix from $1,600 2022-08-23
Openshift Service Mesh CRITICAL 9.8
CVE-2021-3586

A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo…

Mitigation only
Fix from $2,300 2022-08-22
Satellite HIGH 8.8
CVE-2021-3590

A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…

Mitigation only
Fix from $1,950 2022-08-22
Keycloak HIGH 7.5
CVE-2021-3513

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error …

Fix: 13.0.0+
Fix from $1,950 2022-08-22
Openshift Api Management MEDIUM 5.4
CVE-2021-3442

A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s…

Mitigation only
Fix from $1,600 2022-08-22
Openshift Container Platform CRITICAL 9.8
CVE-2020-27836

A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker…

Patch available
Fix from $2,300 2022-08-22
Ansible Automation Platform MEDIUM 6.5
CVE-2022-2568

A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions…

No fix yet
Fix from $1,600 2022-08-18
Jboss A Mq MEDIUM 5.6
CVE-2020-14379

A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info…

Mitigation only
Fix from $1,600 2022-08-16
Process Automation Manager CRITICAL 9.8
CVE-2022-2457

A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as th…

Fix: 7.13.2+
Fix from $2,300 2022-08-10
Process Automation Manager HIGH 8.2
CVE-2022-2458

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack …

Fix: 7.13.1+
Fix from $1,950 2022-08-10
Keycloak HIGH 7.2
CVE-2022-2668

An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature i…

Mitigation only
Fix from $1,950 2022-08-05
Integration Camel K HIGH 7.5
CVE-2022-2053

When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementat…

Fix: 2.2.19+
Fix from $1,950 2022-08-05
Enterprise Linux HIGH 7.5
CVE-2022-2509

A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_p…

Fix: 3.7.7+
Fix from $1,950 2022-08-01