Redhat
redhat
5,681 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,681)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Gnome Redhat2Enterprise Linux Evolution EwsNov 21, 2024 Aug 1, 2019 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 It was discovered evolution-ews before 3.31.3 does not check the validity of SSL certificates. An attacker could abuse this flaw to get confidential information by tricking the user into connecting to a fake server witho...Show more |
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able spoof the UUID of a valid object from another namespace is able to delete children of those objects. Versions 3.6, 3.7, 3.8...Show more |
2Jolokia Redhat2Jolokia OpenstackNov 21, 2024 Aug 1, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origin and referrer header...Show more |
2Apache Redhat3Activemq Jboss A MqJboss FuseNov 21, 2024 Aug 1, 2019 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 It was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service...Show more |
2Redhat Theforeman2Foreman SatelliteNov 21, 2024 Aug 1, 2019 N/A· v4 7.4 HIGH· v3 6.5 MEDIUM· v2 It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access reso...Show more |
2Redhat Theforeman2Foreman Tasks SatelliteNov 21, 2024 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously, commit tasks were searched through find_resource, which performed authorization checks. After the change to Foreman, an un...Show more |
2Icedtea Web Project Redhat6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Jul 31, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Nov 21, 2024 Jul 31, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Pipeline: Shared Groovy Libraries Plugin 2.14 and earlier allowed users with Overall/Read access to obtain limited information about the content of SCM repositories referenced by glo...Show more |
2Jenkins Redhat2Openshift Container Platform Script SecurityNov 21, 2024 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of method pointer expressions allowed attackers to execute arbitrary code in sandboxed scripts. |
2Jenkins Redhat2Openshift Container Platform Script SecurityNov 21, 2024 Jul 31, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.61 and earlier related to the handling of type casts allowed attackers to execute arbitrary code in sandboxed scripts. |
1Redhat 1Openshift Container Platform Nov 21, 2024 Jul 30, 2019 N/A· v4 2.3 LOW· v3 2.1 LOW· v2 OpenShift Container Platform before version 4.1.3 writes OAuth tokens in plaintext to the audit logs for the Kubernetes API server and OpenShift API server. A user with sufficient privileges could recover OAuth tokens fr...Show more |
2Canonical Redhat5Enterprise Linux LibvirtUbuntu Linux+2 moreNov 21, 2024 Jul 30, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of...Show more |
2Debian Redhat3Ansible Debian LinuxOpenstackNov 21, 2024 Jul 30, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advan...Show more |
2Clusterlabs Redhat4Enterprise Linux Enterprise Linux ServerEnterprise Linux Workstation+1 moreNov 21, 2024 Jul 30, 2019 N/A· v4 5.0 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in fence-agents, prior to version 4.3.4, where using non-ASCII characters in a guest VM's comment or other fields would cause fence_rhevm to exit with an exception. In cluster environments, this cou...Show more |
2Openstack Redhat2Ironic Inspector OpenstackNov 21, 2024 Jul 30, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This fu...Show more |
3Linux NetappRedhat20Cloud Backup Developer ToolsEnterprise Linux+17 moreNov 21, 2024 Jul 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by...Show more |
2Eclipse Redhat5Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+2 moreNov 21, 2024 Jul 30, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the...Show more |
6Apache DebianFasterxml+3 more18Banking Platform Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 moreNov 21, 2024 Jul 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more |
7Apple DebianFasterxml+4 more24Active Iq Unified Manager Banking PlatformCommunications Diameter Signaling Router+21 moreNov 21, 2024 Jul 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code ex...Show more |
5F5 LodashNetapp+2 more21Active Iq Unified Manager Banking Extensibility WorkbenchBig Ip Access Policy Manager+18 moreNov 21, 2024 Jul 26, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. |