Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent Secure...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreNov 21, 2024 Mar 3, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without su...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.6 HIGH· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreNov 21, 2024 Mar 3, 2021 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-fr...Show more |
4Fedoraproject GnuNetapp+1 more9Cloud Backup Enterprise LinuxEnterprise Linux Server Aus+6 moreNov 21, 2024 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 6.2 MEDIUM· v2 A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System...Show more |
A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confident...Show more |
1Redhat 13scale Api Management Nov 21, 2024 Feb 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on user-requested date ranges in certain queries allowing a malicious authenticated user to submit a r...Show more |
2Linux Redhat3Enterprise Linux Linux KernelOpenshift Container PlatformNov 21, 2024 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_SYSCALL=y , CONFIG_BPF=y , CONFIG_CGROUPS=y , CONFIG_CGROUP_BPF=y , CONFIG_HARDENED_USERCOPY not set...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Feb 23, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted environment instead of runc. If an attacker can gain access to this build container,...Show more |
1Redhat 3Jboss Fuse Openshift Application RuntimesUndertowNov 21, 2024 Feb 23, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. Th...Show more |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreNov 21, 2024 Feb 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerabili...Show more |
2Netapp Redhat3Active Iq Unified Manager Oncommand Workflow AutomationUndertowNov 21, 2024 Feb 23, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP...Show more |
A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authe...Show more |
A vulnerability was found in all versions of Keycloak Gatekeeper, where on using lower case HTTP headers (via cURL) an attacker can bypass our Gatekeeper. Lower case headers are also accepted by some webservers (e.g. Jet...Show more |
2Podman Project Redhat3Enterprise Linux Openshift Container PlatformPodmanNov 21, 2024 Feb 11, 2021 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not correctly checked. This flaw can be abused by a low-privileged user inside the container to access an...Show more |
1Redhat 4Jboss Fuse KeycloakOpenshift Application Runtimes+1 moreNov 21, 2024 Feb 11, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. |
1Redhat 4Jboss Fuse KeycloakOpenshift Application Runtimes+1 moreNov 21, 2024 Feb 11, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are...Show more |
2Istio Redhat2Istio Openshift Service MeshNov 21, 2024 Jan 29, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A NULL pointer dereference was found in pkg/proxy/envoy/v2/debug.go getResourceVersion in Istio pilot before 1.5.0-alpha.0. If a particular HTTP GET request is made to the pilot API endpoint, it is possible to cause the...Show more |
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token. |
2Keycloak Gatekeeper Project Redhat2Keycloak Gatekeeper Mobile Application PlatformNov 21, 2024 Jan 28, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0 |