Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openshift Container Platform HIGH 7.5
CVE-2020-10752

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…

Patch available
Fix from $1,950 2020-06-12
Undertow HIGH 7.5
CVE-2020-10705

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou…

Fix: 2.1.1+
Fix from $1,950 2020-06-10
Openstack Cinder MEDIUM 6.5
CVE-2020-10755

An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o…

Fix: 14.1.0 / 15.2.0+
Fix from $1,600 2020-06-10
Enterprise Linux MEDIUM 5.0
CVE-2020-10761

An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-cli…

Fix: 5.0.1+
Fix from $1,600 2020-06-09
Openshift Container Platform MEDIUM 6.0
CVE-2020-10749

A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes cluster…

Fix: 0.8.6+
Fix from $1,600 2020-06-03
Libvirt MEDIUM 6.5
CVE-2020-10703

A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a…

Fix: 6.0.0+
Fix from $1,600 2020-06-02
Oddjob MEDIUM 6.3
CVE-2020-10737

A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creati…

Fix: 0.34.5+
Fix from $1,600 2020-05-27
Undertow MEDIUM 6.5
CVE-2020-10719

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allo…

Fix: 2.1.1 / 7.3.13+
Fix from $1,600 2020-05-26
Enterprise Linux Server MEDIUM 6.1
CVE-2020-10751

A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain…

Fix: 5.7+
Fix from $1,600 2020-05-26
Resteasy HIGH 7.5
CVE-2020-1695

A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v…

Fix: 3.12.0 / 4.6.0+
Fix from $1,950 2020-05-19
Keycloak MEDIUM 5.9
CVE-2020-1758

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s…

Fix: 10.0.0+
Fix from $1,600 2020-05-15
Interchange MEDIUM 6.1
CVE-2020-12685

XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentia…

Fix: 5.12.0+
Fix from $1,600 2020-05-15
Ansible MEDIUM 5.0
CVE-2020-10744

An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directiv…

Fix: after 3.6.4
Fix from $1,600 2020-05-15
Keycloak HIGH 8.8
CVE-2020-1714

A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an…

Fix: 11.0.0+
Fix from $1,950 2020-05-13
Jboss Fuse HIGH 8.8
CVE-2020-1718

A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the …

Fix: 8.0.0+
Fix from $1,950 2020-05-12
Ansible Engine MEDIUM 5.0
CVE-2020-1746

A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well a…

Fix: 2.7.17 / 2.8.11+
Fix from $1,600 2020-05-12
Openshift Container Platform MEDIUM 6.6
CVE-2020-10706

A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allow…

Mitigation only
Fix from $1,600 2020-05-12
Ansible Engine MEDIUM 5.5
CVE-2020-10685

A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as An…

Fix: 2.7.17 / 2.8.11+
Fix from $1,600 2020-05-11
Keycloak MEDIUM 5.5
CVE-2020-1698

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…

Fix: 9.0.0+
Fix from $1,600 2020-05-11
Keycloak HIGH 7.2
CVE-2019-10169

A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authent…

Fix: 8.0.0+
Fix from $1,950 2020-05-08
Keycloak HIGH 7.2
CVE-2019-10170

A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an a…

Fix: 8.0.0+
Fix from $1,950 2020-05-08
Hibernate Validator MEDIUM 5.3
CVE-2020-10693

A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua…

Fix: 6.0.20 / 6.1.5+
Fix from $1,600 2020-05-06
Ansible Engine MEDIUM 5.2
CVE-2020-10691

An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extract…

Fix: 2.9.7+
Fix from $1,600 2020-04-30
Libvirt MEDIUM 6.5
CVE-2020-12430

An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the…

Fix: 6.1.0+
Fix from $1,600 2020-04-28
Undertow CRITICAL 9.8
CVE-2020-1745

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final …

Fix: after 2.0.29
Fix from $2,300 2020-04-28
Openshift Service Mesh HIGH 8.6
CVE-2020-1762

An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote atta…

Fix: 1.15.1+
Fix from $1,950 2020-04-27
Enterprise Linux MEDIUM 5.3
CVE-2020-1722

A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password has…

Fix: after 4.8.0
Fix from $1,600 2020-04-27
Openshift Container Platform MEDIUM 5.9
CVE-2020-1741

A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during …

Mitigation only
Fix from $1,600 2020-04-24
Ceph Storage MEDIUM 6.1
CVE-2020-1760

A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS …

Fix: 14.2.21+
Fix from $1,600 2020-04-23
Openshift Container Platform HIGH 8.2
CVE-2020-10712

A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a…

Fix: after 4.1
Fix from $1,950 2020-04-22