Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 3Jboss Fuse KeycloakOpenshift Application RuntimesNov 21, 2024 May 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application. |
3Canonical LinuxRedhat4Enterprise Linux Enterprise MrgLinux Kernel+1 moreNov 21, 2024 May 12, 2020 N/A· v4 5.3 MEDIUM· v3 4.4 MEDIUM· v2 A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent pro...Show more |
2Debian Redhat3Ansible Engine Ansible TowerDebian LinuxNov 21, 2024 May 12, 2020 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 A flaw was found in the Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 May 12, 2020 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then u...Show more |
1Redhat 3Keycloak Openshift Application RuntimesSingle Sign OnNov 21, 2024 May 11, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section. |
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality. |
2Debian Redhat6Ansible Engine Ansible TowerCeph Storage+3 moreNov 21, 2024 May 11, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 whe...Show more |
6Canonical DebianLinux+3 more22Active Iq Unified Manager Debian LinuxElement Software+19 moreNov 21, 2024 May 8, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp device file (like /d...Show more |
2Linux Redhat2Enterprise Mrg Linux KernelNov 21, 2024 May 8, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impac...Show more |
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to con...Show more |
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to...Show more |
4Ibm OracleQuarkus+1 more7Hibernate Validator Jboss Enterprise Application PlatformQuarkus+4 moreNov 21, 2024 May 6, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in Hibernate Validator version 6.1.2.Final. A bug in the message interpolation processor enables invalid EL expressions to be evaluated as if they were valid. This flaw allows attackers to bypass input s...Show more |
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential...Show more |
1Redhat 4Jboss Enterprise Application Platform Jboss Enterprise Application Platform Continuous DeliveryOpenshift Application Runtimes+1 moreNov 21, 2024 May 4, 2020 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead t...Show more |
1Redhat 2Ansible Engine Ansible TowerNov 21, 2024 Apr 30, 2020 N/A· v4 5.2 MEDIUM· v3 3.6 LOW· v2 An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install. When extracting a collection .tar.gz file, the directory is created without sanitiz...Show more |
3Fedoraproject GrafanaRedhat4Ceph Storage Enterprise LinuxFedora+1 moreNov 21, 2024 Apr 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive inform...Show more |
1Redhat 2Enterprise Linux LibvirtNov 21, 2024 Apr 28, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving d...Show more |
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated att...Show more |
2Kiali Redhat2Kiali Openshift Service MeshNov 21, 2024 Apr 27, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using tha...Show more |
2Freeipa Redhat2Enterprise Linux FreeipaNov 21, 2024 Apr 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.4 MEDIUM· v2 A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of servic...Show more |