Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-5156 A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application … Enterprise Linux 2.39+ Fix from $1,9502023-09-25 MEDIUM 5.5 CVE-2023-1633 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining acce… Openstack Platform Mitigation only Fix from $1,6002023-09-24 MEDIUM 5.0 CVE-2023-1625 An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reve… Openstack Platform Patch available Fix from $1,6002023-09-24 MEDIUM 5.0 CVE-2023-1636 A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configura… Openstack Platform Mitigation only Fix from $1,6002023-09-24 CRITICAL 9.8 CVE-2022-4039 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This … Single Sign On Mitigation only Fix from $2,3002023-09-22 CRITICAL 9.1 CVE-2022-3874 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm… Satellite Mitigation only Fix from $2,3002023-09-22 HIGH 7.5 CVE-2022-3596 An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discoveri… Openstack Platform Mitigation only Fix from $1,9502023-09-20 MEDIUM 6.8 CVE-2022-3916 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not clear… Keycloak 20.0.2+ Fix from $1,6002023-09-20 CRITICAL 9.1 CVE-2023-0118 An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on … Satellite 6.13.3+ Fix from $2,3002023-09-20 CRITICAL 9.1 CVE-2023-0462 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste… Satellite 3.8.0+ Fix from $2,3002023-09-20 HIGH 8.1 CVE-2023-4853 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulti… Build Of Optaplanner 1.10.2 / 2.13.8+ Fix from $1,9502023-09-20 MEDIUM 6.5 CVE-2023-4527 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode v… Codeready Linux Builder Eus No fix yet Fix from $1,6002023-09-18 MEDIUM 5.9 CVE-2023-4806 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an … Codeready Linux Builder Eus Mitigation only Fix from $1,6002023-09-18 CRITICAL 9.8 CVE-2023-0923 A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making … Openshift Data Science 1.22.1-3+ Fix from $2,3002023-09-15 HIGH 7.5 CVE-2022-3261 A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading … Openstack Platform Mitigation only Fix from $1,9502023-09-15 HIGH 7.5 CVE-2023-0813 A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentic… Network Observability Mitigation only Fix from $1,9502023-09-15 MEDIUM 6.5 CVE-2023-4959 A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, i… Quay Mitigation only Fix from $1,6002023-09-15 HIGH 7.5 CVE-2023-1108 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, wh… Build Of Quarkus Mitigation only Fix from $1,9502023-09-14 MEDIUM 5.6 CVE-2023-3301 A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci fr… Enterprise Linux after 8.0.3 Fix from $1,6002023-09-13 HIGH 8.2 CVE-2023-2680 This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 … Enterprise Linux Mitigation only Fix from $1,9502023-09-13 MEDIUM 6.5 CVE-2023-3255 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when in… Enterprise Linux after 8.0.3 Fix from $1,6002023-09-13 MEDIUM 5.9 CVE-2023-4813 A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application… Enterprise Linux Patch available Fix from $1,6002023-09-12 HIGH 8.8 CVE-2023-4918 A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "pa… Keycloak Mitigation only Fix from $1,9502023-09-12 MEDIUM 5.4 CVE-2023-0119 A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As… Satellite Mitigation only Fix from $1,6002023-09-12 HIGH 8.8 CVE-2022-1415 A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated a… Decision Manager Mitigation only Fix from $1,9502023-09-11 MEDIUM 6.5 CVE-2023-38201 A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allo… Enterprise Linux Patch available Fix from $1,6002023-08-25 MEDIUM 5.5 CVE-2023-4042 A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. Th… Codeready Linux Builder No fix yet Fix from $1,6002023-08-23 HIGH 7.8 CVE-2023-3899 A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.red… Subscription Manager 1.28.39 / 1.29.37+ Fix from $1,9502023-08-23 MEDIUM 6.5 CVE-2023-4456 A flaw was found in openshift-logging LokiStack. The key used for caching is just the token, which is too broad. This issue allows a user with a toke… Openshift Logging Mitigation only Fix from $1,6002023-08-21 MEDIUM 6.5 CVE-2022-40982 Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may al… Enterprise Linux 20230808+ Fix from $1,6002023-08-11