Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-3914 It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cro… Build Of Quarkus 2.7.5+ Fix from $1,6002022-08-25 HIGH 7.8 CVE-2022-0135 An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially… Enterprise Linux 0.10.0+ Fix from $1,9502022-08-25 HIGH 8.1 CVE-2021-4125 It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all J… Openshift 4.6.52 / 4.7.40+ Fix from $1,9502022-08-24 HIGH 7.8 CVE-2021-4041 A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interface.run_command, can lead to pa… Ansible Runner 2.1.0+ Fix from $1,9502022-08-24 HIGH 7.5 CVE-2021-4213 A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the se… Enterprise Linux 4.9.3 / 5.1.0+ Fix from $1,9502022-08-24 MEDIUM 6.7 CVE-2021-4178 A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configure… Fabric8 Kubernetes 5.0.3 / 5.1.2+ Fix from $1,6002022-08-24 MEDIUM 6.5 CVE-2021-4209 A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause … Enterprise Linux 3.7.3+ Fix from $1,6002022-08-24 MEDIUM 6.0 CVE-2021-4158 A NULL pointer dereference issue was found in the ACPI code of QEMU. A malicious, privileged user within the guest could use this flaw to crash the Q… Enterprise Linux 7.0.0+ Fix from $1,6002022-08-24 MEDIUM 5.3 CVE-2021-4040 A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. T… Amq Broker 2.19.1 / 7.10.0+ Fix from $1,6002022-08-24 MEDIUM 6.5 CVE-2021-3975 A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads with… Libvirt 7.1.0+ Fix from $1,6002022-08-23 MEDIUM 5.5 CVE-2021-3917 A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw … Coreos Installer 0.10.0+ Fix from $1,6002022-08-23 HIGH 7.5 CVE-2021-3905 A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust av… Enterprise Linux Fast Datapath 2.17.0+ Fix from $1,9502022-08-23 MEDIUM 6.8 CVE-2021-3827 A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an at… Keycloak 18.0.0+ Fix from $1,6002022-08-23 HIGH 7.5 CVE-2021-3690 A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cau… Fuse 2.0.40 / 2.2.10+ Fix from $1,9502022-08-23 MEDIUM 6.6 CVE-2021-3701 A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world R/W locations. This flaw all… Ansible Runner Patch available Fix from $1,6002022-08-23 MEDIUM 6.5 CVE-2021-3670 MaxQueryDuration not honoured in Samba AD DC LDAP Storage 4.16.0+ Fix from $1,6002022-08-23 MEDIUM 6.3 CVE-2021-3702 A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a temporary directory, substitute… Ansible Runner Patch available Fix from $1,6002022-08-23 MEDIUM 5.4 CVE-2020-35509 A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because… Keycloak Mitigation only Fix from $1,6002022-08-23 CRITICAL 9.8 CVE-2021-3586 A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify which ports may be accessed, allo… Openshift Service Mesh Mitigation only Fix from $2,3002022-08-22 HIGH 8.8 CVE-2021-3590 A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output… Satellite Mitigation only Fix from $1,9502022-08-22 HIGH 7.5 CVE-2021-3513 A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error … Keycloak 13.0.0+ Fix from $1,9502022-08-22 MEDIUM 5.4 CVE-2021-3442 A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated user to inject scripts into s… Openshift Api Management Mitigation only Fix from $1,6002022-08-22 CRITICAL 9.8 CVE-2020-27836 A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker… Openshift Container Platform Patch available Fix from $2,3002022-08-22 MEDIUM 6.5 CVE-2022-2568 A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a remote authenticated user with 'change user' permissions… Ansible Automation Platform No fix yet Fix from $1,6002022-08-18 MEDIUM 5.6 CVE-2020-14379 A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info… Jboss A Mq Mitigation only Fix from $1,6002022-08-16 CRITICAL 9.8 CVE-2022-2457 A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as th… Process Automation Manager 7.13.2+ Fix from $2,3002022-08-10 HIGH 8.2 CVE-2022-2458 XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack … Process Automation Manager 7.13.1+ Fix from $1,9502022-08-10 HIGH 7.2 CVE-2022-2668 An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature i… Keycloak Mitigation only Fix from $1,9502022-08-05 HIGH 7.5 CVE-2022-2053 When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementat… Integration Camel K 2.2.19+ Fix from $1,9502022-08-05 HIGH 7.5 CVE-2022-2509 A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_p… Enterprise Linux 3.7.7+ Fix from $1,9502022-08-01