Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Openshift Container Platform Nov 21, 2024 Mar 24, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/passw...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Mar 24, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4. An attacker with access to the container could use this flaw to modify /etc/pas...Show more |
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11. An attacker with access to the container could use this flaw to...Show more |
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4. An attacker with access to the container could use this fl...Show more |
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Mar 23, 2021 N/A· v4 5.7 MEDIUM· v3 4.6 MEDIUM· v2 The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows...Show more |
2Netapp Redhat4Active Iq Unified Manager Jboss Enterprise Application PlatformJboss Remoting+1 moreNov 21, 2024 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versi...Show more |
4Debian FedoraprojectPygments+1 more7Debian Linux Enterprise LinuxFedora+4 moreNov 21, 2024 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "except...Show more |
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as wel...Show more |
1Redhat 2Openshift Openshift Container PlatformNov 21, 2024 Mar 19, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently protect the GlusterFS StorageClass against leaking of the restuserkey. An attacker...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Mar 19, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes. Pods with permission to access the host network, ru...Show more |
3Fedoraproject Http Proxy Agent ProjectRedhat4Enterprise Linux FedoraHttp Proxy Agent+1 moreNov 21, 2024 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service throu...Show more |
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Mar 18, 2021 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more |
1Redhat 13scale Api Management Nov 21, 2024 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining access to unauthorized information. Version sh...Show more |
A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or delete a user's container repository. Re...Show more |
2Nbdkit Project Redhat4Enterprise Linux Enterprise Linux ServerNbdkit+1 moreNov 21, 2024 Mar 18, 2021 N/A· v4 3.7 LOW· v3 2.6 LOW· v2 A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by sim...Show more |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreDec 3, 2025 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
1Redhat 2Openshift Builder Openshift Container PlatformNov 21, 2024 Mar 16, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mounted into the container image under construction. An OpenShift user, able to execu...Show more |
It has been discovered in redhat-certification that any unauthorized user may download any file under /var/www/rhcert, provided they know its name. Red Hat Certification 6 and 7 is vulnerable to this issue. |
1Redhat 9A Mq Online Build Of QuarkusCodeready Studio+6 moreNov 21, 2024 Mar 16, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside t...Show more |
1Redhat 2Enterprise Linux LibnbdNov 21, 2024 Mar 15, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in libnbd 1.7.3. An assertion failure in nbd_unlocked_opt_go in ilb/opt.c may lead to denial of service. |