Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A credential leak vulnerability was found in Red Hat Satellite. This flaw exposes the compute resources credentials through VMs that are running on these resources in Satellite. |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreNov 21, 2024 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the Restricted Security Context Constraints (SCC), where it allows pods to craft custom network packets. This flaw allows an attacker to cause a denial of service attack on an OpenShift Container Plat...Show more |
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy. This flaw allows an attacker to gain control of DHCP records from the network. The high...Show more |
2Netapp Redhat3Integration Camel K Oncommand InsightResteasyNov 21, 2024 Jun 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to slower requests with higher CPU time spent searching and adding the entry. This flaw allows...Show more |
1Redhat 2Jboss Enterprise Application Platform WildflyNov 21, 2024 Jun 2, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit th...Show more |
3Infinispan NetappRedhat3Data Grid Infinispan Server RestOncommand InsightNov 21, 2024 Jun 2, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in Infinispan version 10, where it is possible to perform various actions that could have side effects using GET requests. This flaw allows an attacker to perform a cross-site request forgery (CSRF) atta...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformNov 21, 2024 Jun 2, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into p...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Jun 2, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in the Linux kernel. An index buffer overflow during Direct IO write leading to the NFS client to crash. In some cases, a reach out of the index after one memory allocation by kmalloc will cause a kernel...Show more |
A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality. Versions shipped in Red Hat AMQ...Show more |
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra priv...Show more |
3Fedoraproject Nitro Enclaves ProjectRedhat3Enterprise Linux FedoraNitro EnclavesNov 21, 2024 Jun 1, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the s...Show more |
6Debian FedoraprojectNetapp+3 more9Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorDebian Linux+6 moreNov 21, 2024 Jun 1, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by xmllint could trigger a use-after-free. The greatest impact of this flaw is to confidenti...Show more |
2Netlify Redhat2Kiali Operator Openshift Service MeshNov 21, 2024 Jun 1, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use th...Show more |
1Redhat 23scale 3scale Api ManagementNov 21, 2024 Jun 1, 2021 N/A· v4 7.3 HIGH· v3 5.0 MEDIUM· v2 It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap to bypass login controls, and access privileged information, or possibly conduct further attacks. |
2Postgresql Redhat4Enterprise Linux Jboss Enterprise Application PlatformPostgresql+1 moreNov 21, 2024 Jun 1, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write ar...Show more |
1Redhat 3Descision Manager JbpmProcess AutomationNov 21, 2024 Jun 1, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the name of Ruleflow Groups from other projects, despite the user not having access to those projects. The...Show more |
2Openstack Redhat2Neutron Openstack PlatformNov 21, 2024 May 28, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses...Show more |
1Redhat 1389 Directory Server Nov 21, 2024 May 28, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash. |
A flaw was found in SmallRye's API through version 1.6.1. The API can allow other code running within the application server to potentially obtain the ClassLoader, bypassing any permissions checks that should have been a...Show more |