Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file. |
2Heketi Project Redhat4Enterprise Linux Gluster StorageHeketi+1 moreNov 21, 2024 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as g...Show more |
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes recording passwords to the cmd_history.log file which is world-readable...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Nov 21, 2024 Nov 23, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using t...Show more |
2Fedoraproject Redhat4Ceph Ceph StorageFedora+1 moreNov 21, 2024 Nov 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Nov 17, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on U...Show more |
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to h...Show more |
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter. This flaw allows an attacker to perform a Cross-site scripting attack. |
3Fedoraproject Python Rsa ProjectRedhat3Fedora Openstack PlatformPython RsaNov 21, 2024 Nov 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. |
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few sp...Show more |
1Redhat 1Advanced Cluster Management For Kubernetes Nov 21, 2024 Nov 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions. Views created for an admin user would be made available for a short time to users with...Show more |
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets. This flaw allows a remot...Show more |
A Red Hat only CVE-2020-12351 regression issue was found in the way the Linux kernel's Bluetooth implementation handled L2CAP packets with A2MP CID. This flaw allows a remote attacker in an adjacent range to crash the sy...Show more |
2Netapp Redhat10Active Iq Unified Manager FuseJboss Data Grid+7 moreNov 21, 2024 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain...Show more |
2Apple Redhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+6 moreNov 21, 2024 Oct 27, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM...Show more |
2Apple Redhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+6 moreNov 21, 2024 Oct 27, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.1...Show more |
2Apple Redhat10Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+7 moreNov 21, 2024 Oct 27, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Window...Show more |
2Apple Redhat9Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+6 moreNov 21, 2024 Oct 27, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for W...Show more |
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow...Show more |
4Fedoraproject MozillaOracle+1 more6Communications Offline Mediation Controller Communications Pricing Design CenterEnterprise Linux+3 moreNov 21, 2024 Oct 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library....Show more |