Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ceph Storage HIGH 7.2
CVE-2021-20288

An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitiz…

Fix: 14.2.21+
Fix from $1,950 2021-04-15
Enterprise Linux MEDIUM 6.5
CVE-2021-3482

A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size property in Jp2Image::readMetada…

Fix: after 0.27.3
Fix from $1,600 2021-04-08
Satellite MEDIUM 6.3
CVE-2021-3413

A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was identified which will expose Az…

Fix: 2.2.0+
Fix from $1,600 2021-04-08
Ansible MEDIUM 5.5
CVE-2021-3447

A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod…

Fix: 1.2.2 / 3.8.2+
Fix from $1,600 2021-04-01
Openshift Container Platform MEDIUM 6.5
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is u…

Fix: 1.28.1+
Fix from $1,600 2021-04-01
Enterprise Linux HIGH 7.0
CVE-2021-20271

A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to instal…

Fix: 4.15.1.3 / 4.16.1.3+
Fix from $1,950 2021-03-26
Resteasy MEDIUM 5.3
CVE-2021-20289

A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception…

Fix: 1.13.4+
Fix from $1,600 2021-03-26
Enterprise Linux MEDIUM 6.3
CVE-2021-20197

There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When…

Fix: after 2.35
Fix from $1,600 2021-03-26
389 Directory Server MEDIUM 5.3
CVE-2020-35518

When binding against a DN during authentication, the reply from 389-ds-base will be different whether the DN exists or not. This can be used by an un…

Fix: 1.4.3.19 / 1.4.4.13+
Fix from $1,600 2021-03-26
Enterprise Linux CRITICAL 9.8
CVE-2021-3466EPSS 9%

A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attac…

Patch available
Fix from $2,300 2021-03-25
Enterprise Linux MEDIUM 5.5
CVE-2021-3443

A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A sp…

Fix: 2.0.27+
Fix from $1,600 2021-03-25
Enterprise Linux MEDIUM 5.5
CVE-2021-3446

A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the …

Fix: 0.8.2+
Fix from $1,600 2021-03-25
Openshift Container Platform HIGH 7.8
CVE-2019-19354

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hadoop as shipped in Red Hat Openshift 4. An attac…

Fix: 4.4.3+
Fix from $1,950 2021-03-24
Openshift Container Platform HIGH 7.0
CVE-2019-19352

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attac…

Mitigation only
Fix from $1,950 2021-03-24
Openshift Container Platform HIGH 7.0
CVE-2019-19353

An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacke…

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19349

An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat …

No fix yet
Fix from $1,950 2021-03-24
Openshift HIGH 7.8
CVE-2019-19350

An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 an…

No fix yet
Fix from $1,950 2021-03-24
Enterprise Linux MEDIUM 5.7
CVE-2021-3409

The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues pr…

Fix: after 5.2.0
Fix from $1,600 2021-03-23
Jboss Remoting HIGH 7.5
CVE-2019-19343

A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holdi…

Fix: 2.0.25 / 5.0.14+
Fix from $1,950 2021-03-23
Keycloak HIGH 7.5
CVE-2021-20222

A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat …

Fix: 13.0.0+
Fix from $1,950 2021-03-23
Openshift Container Platform HIGH 7.5
CVE-2021-20270

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SM…

Fix: after 2.7.3
Fix from $1,950 2021-03-23
Openshift Container Platform HIGH 7.2
CVE-2019-10200

A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloa…

Patch available
Fix from $1,950 2021-03-19
Openshift MEDIUM 6.3
CVE-2019-10225

A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the…

Mitigation only
Fix from $1,600 2021-03-19
3scale Api Management HIGH 7.5
CVE-2019-14852

A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break…

Mitigation only
Fix from $1,950 2021-03-18
Openshift Container Platform HIGH 7.5
CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle speci…

Fix: 1.0.8 / 2.6.9+
Fix from $1,950 2021-03-18
Openshift Builder HIGH 8.8
CVE-2021-3344

A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into t…

Fix: 4.5.33 / 4.6.16+
Fix from $1,950 2021-03-16
Certification MEDIUM 5.3
CVE-2019-3897

It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. R…

Mitigation only
Fix from $1,600 2021-03-16
Kubernetes Client HIGH 7.4
CVE-2021-20218

A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using …

Fix: 4.7.2 / 4.11.2+
Fix from $1,950 2021-03-16
Certificate System HIGH 8.1
CVE-2021-20179

A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and …

Fix: 10.5.0 / 10.8.0+
Fix from $1,950 2021-03-15
Enterprise Linux CRITICAL 9.8
CVE-2021-20231

A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.

Fix: 3.7.1+
Fix from $2,300 2021-03-12