Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Openshift Container Platform Nov 21, 2024 Apr 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection bet...Show more |
5Canonical DebianFedoraproject+2 more6Ceph Ceph StorageDebian Linux+3 moreNov 21, 2024 Apr 23, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Apr 22, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator allowing an attacker able to gain access to those logs, to read and writ...Show more |
1Redhat 6Jboss Data Grid Jboss Enterprise Application PlatformJboss Fuse+3 moreNov 21, 2024 Apr 21, 2020 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize...Show more |
2Linuxfoundation Redhat2Ceph Ceph StorageNov 21, 2024 Apr 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use thi...Show more |
3Canonical GnuRedhat3Enterprise Linux GlibcUbuntu LinuxNov 21, 2024 Apr 17, 2020 N/A· v4 7.0 HIGH· v3 5.9 MEDIUM· v2 An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address...Show more |
5Debian NetappNtp+2 more17All Flash Fabric Attached Storage 8300 Firmware All Flash Fabric Attached Storage 8700 FirmwareAll Flash Fabric Attached Storage A400 Firmware+14 moreMay 5, 2025 Apr 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled e...Show more |
6Canonical FedoraprojectLibssh+3 more6Cloud Backup Enterprise LinuxFedora+3 moreNov 21, 2024 Apr 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and...Show more |
3Fedoraproject LinuxfoundationRedhat5Ceph Ceph StorageFedora+2 moreNov 21, 2024 Apr 13, 2020 N/A· v4 6.8 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attack...Show more |
3Linux OpensuseRedhat3Enterprise Linux LeapLinux KernelNov 21, 2024 Apr 10, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMO...Show more |
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing se...Show more |
2Quarkus Redhat2Keycloak QuarkusNov 21, 2024 Apr 6, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a...Show more |
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/apb-base, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4. An attacker with access to the...Show more |
An insecure modification vulnerability in the /etc/passwd file was found in the container openshift/mariadb-apb, affecting versions before the following 4.3.5, 4.2.21, 4.1.37, and 3.11.188-4 . An attacker with access to...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraHaproxy+3 moreNov 21, 2024 Apr 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly ca...Show more |
2Buildah Project Redhat3Buildah Enterprise LinuxOpenshift Container PlatformNov 21, 2024 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's...Show more |
3Debian RedhatSystemd Project7Ceph Storage Debian LinuxDiscovery+4 moreNov 21, 2024 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more |
3Fedoraproject OpensuseRedhat8Ansible Engine Ansible TowerBackports Sle+5 moreNov 21, 2024 Mar 31, 2020 N/A· v4 5.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more |
2Dogtagpki Redhat2Certificate System DogtagpkiNov 21, 2024 Mar 31, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 A vulnerability was found in all pki-core 10.x.x version, where the Token Processing Service (TPS) did not properly sanitize several parameters stored for the tokens, possibly resulting in a Stored Cross Site Scripting (...Show more |
2Kiali Redhat2Kiali Openshift Service MeshNov 21, 2024 Mar 26, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 A hard-coded cryptographic key vulnerability in the default configuration file was found in Kiali, all versions prior to 1.15.1. A remote attacker could abuse this flaw by creating their own JWT signed tokens and bypass...Show more |