rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
mcollective has a default password set at install
CFME: CSRF protection vulnerability via permissive check of the referrer header
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of…
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the user session cookie. An attacker could use this to …
Openshift has shell command injection flaws due to unsanitized data being passed into shell commands.
katello-headpin is vulnerable to CSRF in REST API
JBossWeb Bayeux has reflected XSS
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
JBoss KeyCloak: XSS in login-status-iframe.html
openstack-utils openstack-db has insecure password creation
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "bits…
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "iden…
An out-of-bounds read was discovered in OpenCV before 4.1.1. Specifically, variable coarsest_scale is assumed to be greater than or equal to finest_s…
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will…
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iteratio…
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
OpenShift cartridge allows remote URL retrieval
Katello has multiple XSS issues in various entities
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. …
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafte…
In ghostscript before version 9.50, the .buildfont1 procedure did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` rest…
Structured reply is a feature of the newstyle NBD protocol allowing the server to send a reply in chunks. A bounds check which was supposed to test f…
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from …
A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for …