Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Redhat2Ansible Debian LinuxNov 21, 2024 Aug 26, 2020 N/A· v4 7.3 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the re...Show more |
2Oracle Redhat2Ovirt Engine VirtualizationNov 21, 2024 Aug 24, 2020 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary web sites and attempt phishing attacks. Once the target has opened the ma...Show more |
6Canonical DebianLinux+3 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreNov 21, 2024 Aug 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privile...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversio...Show more |
An information disclosure vulnerability was found in Red Hat Quay in versions before 3.3.1. This flaw allows an attacker who can create a build trigger in a repository, to disclose the names of robot accounts and the exi...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not nor...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 6.3 MEDIUM· v3 4.9 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering...Show more |
Red Hat CloudForms before 5.11.7.0 was vulnerable to the User Impersonation authorization flaw which allows malicious attacker to create existent and non-existent role-based access control user, with groups and roles. Wi...Show more |
Red Hat CloudForms 4.7 and 5 is affected by a role-based privilege escalation flaw. An attacker with EVM-Operator group can perform actions restricted only to EVM-Super-administrator group, leads to, exporting or importi...Show more |
Red Hat CloudForms 4.7 and 5 leads to insecure direct object references (IDOR) and functional level access control bypass due to missing privilege check. Therefore, if an attacker knows the right criteria, it is possible...Show more |
In Red Hat CloudForms 4.7 and 5, the read only widgets can be edited by inspecting the forms and dropping the disabled attribute from the fields since there is no server-side validation. This business logic flaw violate...Show more |
A cross-site scripting flaw was found in Report Menu feature of Red Hat CloudForms 4.7 and 5. An attacker could use this flaw to execute a stored XSS attack on an application administrator using CloudForms. |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreNov 21, 2024 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Aug 6, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified i...Show more |
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Aug 6, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a...Show more |
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Aug 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users'...Show more |
It was found that the AMQ Online console is vulnerable to a Cross-Site Request Forgery (CSRF) which is exploitable in cases where preflight checks are not instigated or bypassed. For example authorised users using an old...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreNov 21, 2024 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized m...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreNov 21, 2024 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to re...Show more |
A data exposure flaw was found in Tower, where sensitive data was revealed from the HTTP return error codes. This flaw allows an unauthenticated, remote attacker to retrieve pages from the default organization and verify...Show more |