Redhat
redhat
5,678 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,678)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Libsdl Redhat2Enterprise Linux Simple Directmedia LayerNov 21, 2024 Jan 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL packages, SDL versions through 1.2.15 and 2.x through 2.0.9 has a heap-base...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jan 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found during the upgrade of an existing OpenShift Container Platform 3.x cluster. Using CRI-O, the dockergc service account is assigned to the current namespace of the user performing the upgrade. This flaw ca...Show more |
2Gnu Redhat2Cpio Enterprise LinuxNov 21, 2024 Jan 7, 2020 N/A· v4 7.3 HIGH· v3 6.9 MEDIUM· v2 In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain fil...Show more |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jan 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or higher. A low privileged user could read pod logs to discover secret mater...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Jan 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized informatio...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Jan 7, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client...Show more |
3Fedoraproject RedhatZend3Enterprise Linux FedoraZend FrameworkNov 21, 2024 Jan 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Fo...Show more |
Versions of Foreman as shipped with Red Hat Satellite 6 does not check for a correct CSRF token in the logout action. Therefore, an attacker can log out a user by having them view specially crafted content. |
It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take lon...Show more |
1Redhat 1Subscription Asset Manager Nov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Versions of Katello as shipped with Red Hat Subscription Asset Manager 1.4 are vulnerable to a XSS via HTML in the systems name when registering. |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In JBoss EAP 6 a security domain is configured to use a cache that is shared between all applications that are in the security domain. This could allow an authenticated user in one application to access protected resourc...Show more |
A flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red Hat Quay database could use the tokens to read or write container images stored...Show more |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreNov 21, 2024 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
2Angularjs Redhat3Angularjs Decision ManagerProcess AutomationNov 20, 2025 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, with...Show more |
3Knockoutjs OracleRedhat5Business Intelligence Decision ManagerGoldengate+2 moreNov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 There is a vulnerability in knockout before version 3.5.0-beta, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without va...Show more |
2Python Ecdsa Project Redhat4Ceph Storage OpenstackPython Ecdsa+1 moreNov 21, 2024 Jan 2, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signatur...Show more |
2Infinispan Redhat2Infinispan Jboss Data GridNov 21, 2024 Jan 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in Infinispan through version 9.4.14.Final. An improper implementation of the session fixation protection in the Spring Session integration can result in incorrect session handling. |
2Redhat Samba2Enterprise Linux SambaNov 21, 2024 Dec 31, 2019 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file...Show more |
1Redhat 1Mrg Management Console Nov 21, 2024 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it. |
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the credential and the Au...Show more |