Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-2738 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t… Enterprise Linux Server Mitigation only Fix from $1,9502022-09-01 MEDIUM 6.6 CVE-2022-2447 A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be rev… Openstack Platform No fix yet Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-2238 A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets pa… Advanced Cluster Management For Kubernetes Mitigation only Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-2403 A credentials leak was found in the OpenShift Container Platform. The private key for the external cluster certificate was stored incorrectly in the … Openshift Patch available Fix from $1,6002022-09-01 MEDIUM 6.3 CVE-2022-1677 In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of th… Openshift Container Platform Patch available Fix from $1,6002022-09-01 MEDIUM 5.3 CVE-2022-2739 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing t… Enterprise Linux Server Mitigation only Fix from $1,6002022-09-01 MEDIUM 6.5 CVE-2022-1632 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serv… Ansible Automation Platform Mitigation only Fix from $1,6002022-09-01 HIGH 8.8 CVE-2022-1271 An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a… Jboss Data Grid 1.12 / 5.2.5+ Fix from $1,9502022-08-31 HIGH 7.5 CVE-2022-1259 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of servic… Build Of Quarkus after 2.2.17 Fix from $1,9502022-08-31 HIGH 7.5 CVE-2022-1319 A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set ev… Openshift Application Runtimes 2.2.17+ Fix from $1,9502022-08-31 HIGH 7.5 CVE-2022-0934 A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dns… Enterprise Linux 2.87+ Fix from $1,9502022-08-29 MEDIUM 5.5 CVE-2022-0852 There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow una… Enterprise Linux 0.26+ Fix from $1,6002022-08-29 HIGH 7.8 CVE-2022-0358 A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local… Enterprise Linux 6.2.0-7+ Fix from $1,9502022-08-29 MEDIUM 6.5 CVE-2022-0669 A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_IN… Openshift Container Platform 22.03+ Fix from $1,6002022-08-29 MEDIUM 5.5 CVE-2022-0851 There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription… Enterprise Linux No fix yet Fix from $1,6002022-08-29 MEDIUM 6.7 CVE-2022-34301 A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot pro… Enterprise Linux 2022-06-01+ Fix from $1,6002022-08-26 MEDIUM 6.7 CVE-2022-34302 A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot prote… Enterprise Linux 2022-06-01+ Fix from $1,6002022-08-26 MEDIUM 6.7 CVE-2022-34303 A flaw was found in Eurosoft bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In … Enterprise Linux 2022-06-01+ Fix from $1,6002022-08-26 HIGH 7.5 CVE-2022-0084 A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. … Integration Camel K 3.8.7+ Fix from $1,9502022-08-26 MEDIUM 5.5 CVE-2022-0175 A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly initialize memory when allocating a host-backed mem… Enterprise Linux Patch available Fix from $1,6002022-08-26 MEDIUM 5.4 CVE-2022-0225 A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from t… Keycloak No fix yet Fix from $1,6002022-08-26 HIGH 7.5 CVE-2021-3632 A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered… Keycloak 7.4.9 / 15.1.0+ Fix from $1,9502022-08-26 HIGH 7.5 CVE-2021-3703 It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Se… Openshift Serverless 1.17.0+ Fix from $1,9502022-08-26 HIGH 7.5 CVE-2021-3859 A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carr… Jboss Enterprise Application Platform 2.2.15+ Fix from $1,9502022-08-26 MEDIUM 5.3 CVE-2021-3754 A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may caus… Keycloak Mitigation only Fix from $1,6002022-08-26 HIGH 8.1 CVE-2021-3414 A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage othe… Satellite Mitigation only Fix from $1,9502022-08-26 MEDIUM 6.7 CVE-2021-35939 It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to … Enterprise Linux 4.18+ Fix from $1,6002022-08-26 HIGH 8.8 CVE-2021-4112 A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the p… Ansible Automation Platform Early Access Mitigation only Fix from $1,9502022-08-25 MEDIUM 6.5 CVE-2021-3979 A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algo… Ceph Storage Patch available Fix from $1,6002022-08-25 MEDIUM 6.4 CVE-2021-35937 A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response … Enterprise Linux 4.18.0+ Fix from $1,6002022-08-25