Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2020-10752 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa… Openshift Container Platform Patch available Fix from $1,9502020-06-12 HIGH 7.5 CVE-2020-10705 A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an ou… Undertow 2.1.1+ Fix from $1,9502020-06-10 MEDIUM 6.5 CVE-2020-10755 An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before o… Openstack Cinder 14.1.0 / 15.2.0+ Fix from $1,6002020-06-10 MEDIUM 5.0 CVE-2020-10761 An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-cli… Enterprise Linux 5.0.1+ Fix from $1,6002020-06-09 MEDIUM 6.0 CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes cluster… Openshift Container Platform 0.8.6+ Fix from $1,6002020-06-03 MEDIUM 6.5 CVE-2020-10703 A NULL pointer dereference was found in the libvirt API responsible introduced in upstream version 3.10.0, and fixed in libvirt 6.0.0, for fetching a… Libvirt 6.0.0+ Fix from $1,6002020-06-02 MEDIUM 6.3 CVE-2020-10737 A race condition was found in the mkhomedir tool shipped with the oddjob package in versions before 0.34.5 and 0.34.6 wherein, during the home creati… Oddjob 0.34.5+ Fix from $1,6002020-05-27 MEDIUM 6.5 CVE-2020-10719 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allo… Undertow 2.1.1 / 7.3.13+ Fix from $1,6002020-05-26 MEDIUM 6.1 CVE-2020-10751 A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain… Enterprise Linux Server 5.7+ Fix from $1,6002020-05-26 HIGH 7.5 CVE-2020-1695 A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input v… Resteasy 3.12.0 / 4.6.0+ Fix from $1,9502020-05-19 MEDIUM 5.9 CVE-2020-1758 A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP s… Keycloak 10.0.0+ Fix from $1,6002020-05-15 MEDIUM 6.1 CVE-2020-12685 XSS in the admin help system admin/help.html and admin/quicklinks.html in Interchange 4.7.0 through 5.11.x allows remote attackers to steal credentia… Interchange 5.12.0+ Fix from $1,6002020-05-15 MEDIUM 5.0 CVE-2020-10744 An incomplete fix was found for the fix of the flaw CVE-2020-1733 ansible: insecure temporary directory when running become_user from become directiv… Ansible after 3.6.4 Fix from $1,6002020-05-15 HIGH 8.8 CVE-2020-1714 A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an… Keycloak 11.0.0+ Fix from $1,9502020-05-13 HIGH 8.8 CVE-2020-1718 A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the … Jboss Fuse 8.0.0+ Fix from $1,9502020-05-12 MEDIUM 5.0 CVE-2020-1746 A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well a… Ansible Engine 2.7.17 / 2.8.11+ Fix from $1,6002020-05-12 MEDIUM 6.6 CVE-2020-10706 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allow… Openshift Container Platform Mitigation only Fix from $1,6002020-05-12 MEDIUM 5.5 CVE-2020-10685 A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as An… Ansible Engine 2.7.17 / 2.8.11+ Fix from $1,6002020-05-11 MEDIUM 5.5 CVE-2020-1698 A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe… Keycloak 9.0.0+ Fix from $1,6002020-05-11 HIGH 7.2 CVE-2019-10169 A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authent… Keycloak 8.0.0+ Fix from $1,9502020-05-08 HIGH 7.2 CVE-2019-10170 A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an a… Keycloak 8.0.0+ Fix from $1,9502020-05-08 MEDIUM 5.3 CVE-2020-10693 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evalua… Hibernate Validator 6.0.20 / 6.1.5+ Fix from $1,6002020-05-06 MEDIUM 5.2 CVE-2020-10691 An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extract… Ansible Engine 2.9.7+ Fix from $1,6002020-04-30 MEDIUM 6.5 CVE-2020-12430 An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the… Libvirt 6.1.0+ Fix from $1,6002020-04-28 CRITICAL 9.8 CVE-2020-1745 A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final … Undertow after 2.0.29 Fix from $2,3002020-04-28 HIGH 8.6 CVE-2020-1762 An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote atta… Openshift Service Mesh 1.15.1+ Fix from $1,9502020-04-27 MEDIUM 5.3 CVE-2020-1722 A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password has… Enterprise Linux after 4.8.0 Fix from $1,6002020-04-27 MEDIUM 5.9 CVE-2020-1741 A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during … Openshift Container Platform Mitigation only Fix from $1,6002020-04-24 MEDIUM 6.1 CVE-2020-1760 A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS … Ceph Storage 14.2.21+ Fix from $1,6002020-04-23 HIGH 8.2 CVE-2020-10712 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a… Openshift Container Platform after 4.1 Fix from $1,9502020-04-22