Vulnerability index

Browse CVEs

2,586 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2020-1757 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.… Undertow 2.1.0+ Fix from $1,9502020-04-21 HIGH 7.5 CVE-2020-1699 A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed i… Ceph Storage Mitigation only Fix from $1,9502020-04-21 HIGH 7.0 CVE-2020-1751 An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function… Enterprise Linux 2.31+ Fix from $1,9502020-04-17 HIGH 7.5 CVE-2020-11868 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet wi… Enterprise Linux 4.3.100+ Fix from $1,9502020-04-17 MEDIUM 6.8 CVE-2020-1759 A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in … Ceph Storage 14.2.21+ Fix from $1,6002020-04-13 MEDIUM 6.8 CVE-2020-2732 A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under s… Enterprise Linux Patch available Fix from $1,6002020-04-08 MEDIUM 5.4 CVE-2020-1728 A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HT… Keycloak 10.0.0+ Fix from $1,6002020-04-06 HIGH 7.0 CVE-2019-19346 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the follow… Openshift 3.11.188-4 / 4.1.37+ Fix from $1,9502020-04-02 HIGH 7.0 CVE-2019-19348 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following… Openshift 3.11.188-4 / 4.1.37+ Fix from $1,9502020-04-02 HIGH 8.8 CVE-2020-10696 A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious containe… Openshift Container Platform 1.14.5+ Fix from $1,9502020-03-31 HIGH 7.8 CVE-2020-1712 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus… Ceph Storage after 244 Fix from $1,9502020-03-31 MEDIUM 5.6 CVE-2019-14905 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos… Ansible Engine 2.7.16 / 2.8.8+ Fix from $1,6002020-03-31 HIGH 8.6 CVE-2020-1764 A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker co… Openshift Service Mesh 1.15.1+ Fix from $1,9502020-03-26 MEDIUM 5.6 CVE-2020-1744 A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failur… Keycloak 9.0.1+ Fix from $1,6002020-03-24 HIGH 7.1 CVE-2020-10684 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a … Ansible 2.7.17 / 2.8.9+ Fix from $1,9502020-03-24 HIGH 7.8 CVE-2019-19345 A vulnerability was found in all openshift/mediawiki-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pass… Openshift 4.3+ Fix from $1,9502020-03-20 HIGH 7.8 CVE-2020-1709 A vulnerability was found in all openshift/mediawiki 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd f… Openshift 4.3+ Fix from $1,9502020-03-20 HIGH 7.0 CVE-2020-1707 A vulnerability was found in all openshift/postgresql-apb 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/pas… Openshift 4.3+ Fix from $1,9502020-03-20 MEDIUM 5.4 CVE-2020-1696 A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a… Certificate System after 10.8.3 Fix from $1,6002020-03-20 MEDIUM 6.1 CVE-2019-10179 A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery re… Enterprise Linux after 10.8.3 Fix from $1,6002020-03-20 MEDIUM 6.1 CVE-2019-10221 A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw… Enterprise Linux after 10.8.3 Fix from $1,6002020-03-20 HIGH 7.0 CVE-2020-1705 A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerab… Template Service Broker Operator 4.3.0+ Fix from $1,9502020-03-19 MEDIUM 6.1 CVE-2019-19336 A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were includ… Virtualization 4.3.8+ Fix from $1,6002020-03-19 MEDIUM 5.7 CVE-2019-20485 qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a… Libvirt 6.0.0+ Fix from $1,6002020-03-19 HIGH 7.0 CVE-2019-19351 An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/jenkins. An attacker with access to the container… Openshift Mitigation only Fix from $1,9502020-03-18 HIGH 7.0 CVE-2019-19355 An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ocp-release-operator-sdk. An attacker with access to the co… Openshift Mitigation only Fix from $1,9502020-03-18 MEDIUM 5.5 CVE-2020-1753 A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2… Ansible Engine 2.7.18 / 2.8.11+ Fix from $1,6002020-03-16 CRITICAL 9.1 CVE-2019-14887 A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An… Jboss Data Grid Mitigation only Fix from $2,3002020-03-16 HIGH 8.8 CVE-2020-10531 An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer ove… Enterprise Linux Desktop 10.21.0 / 80.0.3987.122+ Fix from $1,9502020-03-12 MEDIUM 5.0 CVE-2020-1733 A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged bec… Ansible 2.8.8+ Fix from $1,6002020-03-11