CVEs (326)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianHp+3 more15Debian Linux Enterprise LinuxEnterprise Linux Desktop+12 moreJun 17, 2026 Apr 23, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 7u211 and 8u202. Difficult to exploit vulnerability allows unauthenticated attacker with netw...Show more |
7Apache CanonicalDebian+4 more17Cassandra Debian LinuxEnterprise Linux+14 moreJun 17, 2026 Apr 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit...Show more |
7Canonical DebianHp+4 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreJun 17, 2026 Apr 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Easily exploit...Show more |
2Heketi Project Redhat2Heketi Openshift Container PlatformJun 17, 2026 Apr 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3....Show more |
3Kubernetes NetappRedhat3Kubernetes Openshift Container PlatformTridentJun 17, 2026 Apr 22, 2019 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is spec...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable...Show more |
3Jenkins OracleRedhat3Communications Cloud Native Core Automated Test Suite JenkinsOpenshift Container PlatformJun 17, 2026 Apr 10, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2.160 and newer, would remain authenticated in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, because the fix...Show more |
8Apache CanonicalDebian+5 more27Communications Session Report Manager Communications Session Route ManagerDebian Linux+24 moreJun 17, 2026 Apr 8, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) cou...Show more |
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 1, 2019 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a sepa...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Apr 1, 2019 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on th...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patc...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
2Prometheus Redhat2Openshift Container Platform PrometheusJun 17, 2026 Mar 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowin...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Mar 25, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascrip...Show more |
7Canonical DebianFedoraproject+4 more15Active Iq Performance Analytics Services Debian LinuxElement Software Management Node+12 moreJun 17, 2026 Mar 21, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. |
4Canonical HaproxyOpensuse+1 more5Enterprise Linux HaproxyLeap+2 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra byte...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpa...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database acce...Show more |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, e...Show more |