Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2023-0664 A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows inst… Enterprise Linux 8.0.0+ Fix from $1,9502023-03-29 MEDIUM 6.1 CVE-2022-2237 A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio… Keycloak Node.js Adapter Mitigation only Fix from $1,6002023-03-27 HIGH 7.1 CVE-2023-1380EPSS 17% A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel.… Enterprise Linux 4.14.315 / 4.19.283+ Fix from $1,9502023-03-27 MEDIUM 6.8 CVE-2023-0778 A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal file in a volume with a syml… Enterprise Linux Mitigation only Fix from $1,6002023-03-27 MEDIUM 5.5 CVE-2021-3684 A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the… Openshift Assisted Installer 1.0.25.3+ Fix from $1,6002023-03-24 MEDIUM 6.5 CVE-2023-0056 An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated r… Ceph Storage Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3146 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2022-3101 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. T… Openstack Mitigation only Fix from $1,6002023-03-23 HIGH 8.6 CVE-2022-4904 A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbit… Software Collections 1.19.0+ Fix from $1,9502023-03-06 MEDIUM 6.5 CVE-2022-3854 A flaw was found in Ceph, relating to the URL processing on RGW backends. An attacker can exploit the URL processing by providing a null URL to crash… Ceph Storage Mitigation only Fix from $1,6002023-03-06 HIGH 8.8 CVE-2019-8720 KEV A vulnerability was found in WebKit. The flaw is triggered when processing maliciously crafted web content that may lead to arbitrary code execution.… Codeready Linux Builder Mitigation only Fix from $1,9502023-03-06 MEDIUM 6.5 CVE-2022-3277 An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security gr… Openstack Platform 18.6.0 / 19.5.0+ Fix from $1,6002023-03-06 HIGH 7.0 CVE-2023-27561 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an att… Openshift Container Platform 1.1.5+ Fix from $1,9502023-03-03 MEDIUM 5.5 CVE-2023-1055 A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attrib… Directory Server Mitigation only Fix from $1,6002023-02-27 HIGH 7.5 CVE-2022-4492 The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least… Build Of Quarkus Mitigation only Fix from $1,9502023-02-23 MEDIUM 6.1 CVE-2023-0044 If the Quarkus Form Authentication session cookie Path attribute is set to `/` then a cross-site attack may be initiated which might lead to the Info… Build Of Quarkus 2.13.7+ Fix from $1,6002023-02-23 MEDIUM 5.5 CVE-2023-0482 In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files … Resteasy Patch available Fix from $1,6002023-02-17 HIGH 7.4 CVE-2023-0361 A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the … Enterprise Linux Patch available Fix from $1,9502023-02-15 HIGH 8.8 CVE-2022-4254 sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters Enterprise Linux Patch available Fix from $1,9502023-02-01 MEDIUM 6.3 CVE-2023-0229 A flaw was found in github.com/openshift/apiserver-library-go, used in OpenShift 4.12 and 4.11, that contains an issue that can allow low-privileged … Openshift Mitigation only Fix from $1,6002023-01-26 MEDIUM 5.9 CVE-2022-3100 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. Openstack Mitigation only Fix from $1,6002023-01-18 MEDIUM 5.3 CVE-2023-0296 The Birthday attack against 64-bit block ciphers flaw (CVE-2016-2183) was reported for the health checks port (9979) on etcd grpc-proxy component. Ev… Openshift Mitigation only Fix from $1,6002023-01-17 HIGH 7.8 CVE-2022-3650 A privilege escalation flaw was found in Ceph. Ceph-crash.service allows a local attacker to escalate privileges to root in the form of a crash dump,… Ceph No fix yet Fix from $1,9502023-01-17 CRITICAL 9.1 CVE-2022-3782EPSS 6% keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An a… Keycloak Mitigation only Fix from $2,3002023-01-13 HIGH 7.8 CVE-2022-3841 RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Re… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,9502023-01-13 HIGH 7.4 CVE-2022-3143 wildfly-elytron: possible timing attacks via use of unsafe comparator. A flaw was found in Wildfly-elytron. Wildfly-elytron uses java.util.Arrays.equ… Wildfly Elytron Mitigation only Fix from $1,9502023-01-13 MEDIUM 6.5 CVE-2023-0105 A flaw was found in Keycloak. This flaw allows impersonation and lockout due to the email trust not being handled correctly in Keycloak. An attacker … Keycloak Mitigation only Fix from $1,6002023-01-13 HIGH 7.5 CVE-2022-4743 A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to c… Enterprise Linux 2.26.0+ Fix from $1,9502023-01-12 HIGH 7.8 CVE-2022-3715 A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. Enterprise Linux 5.1.8+ Fix from $1,9502023-01-05 MEDIUM 5.9 CVE-2021-4294 A vulnerability was found in OpenShift OSIN. It has been classified as problematic. This affects the function ClientSecretMatches/CheckClientSecret. … Openshift Container Platform Patch available Fix from $1,6002022-12-28