Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Openshift Container Platform Jun 17, 2026 Apr 1, 2019 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the /oauth/token/request custom endpoint of the OpenShift OAuth server allowing for XSS generation of CLI tokens due to missing X-Frame-Options and CSRF protections. If not otherwise prevented, a sepa...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Apr 1, 2019 N/A· v4 5.5 MEDIUM· v3 5.8 MEDIUM· v2 The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on th...Show more |
2Kubernetes Redhat2Kubernetes Openshift Container PlatformJun 17, 2026 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patc...Show more |
2Jenkins Redhat2Openshift Container Platform Pipeline\Jun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Pipeline: Groovy Plugin 2.64 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
2Jenkins Redhat2Openshift Container Platform Script SecurityJun 17, 2026 Mar 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.55 and earlier allows attackers to invoke arbitrary constructors in sandboxed scripts. |
When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain...Show more |
4Fedoraproject OpensuseRedhat+1 more8Edk Ii Enterprise LinuxEnterprise Linux Eus+5 moreJun 17, 2026 Mar 27, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access. |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unre...Show more |
5Debian FedoraprojectOpensuse+2 more6Cloudforms Debian LinuxFedora+3 moreJun 17, 2026 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesyste...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more4Enterprise Linux FedoraMod Auth Mellon+1 moreJun 17, 2026 Mar 27, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert...Show more |
A NULL pointer dereference flaw was discovered in libvirt before version 5.0.0 in the way it gets interface information through the QEMU agent. An attacker in a guest VM can use this flaw to crash libvirtd and cause a de...Show more |
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not r...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Mar 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privi...Show more |
4Canonical FedoraprojectMod Auth Mellon Project+1 more10Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreJun 17, 2026 Mar 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in mod_auth_mellon before v0.14.2. If Apache is configured as a reverse proxy and mod_auth_mellon is configured to only let through authenticated users (with the require valid-user directive), a...Show more |
2Openstack Redhat2Ceilometer OpenstackJun 17, 2026 Mar 26, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated. |
2Prometheus Redhat2Openshift Container Platform PrometheusJun 17, 2026 Mar 26, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A stored, DOM based, cross-site scripting (XSS) flaw was found in Prometheus before version 2.7.1. An attacker could exploit this by convincing an authenticated user to visit a crafted URL on a Prometheus server, allowin...Show more |
3Cockpit Project FedoraprojectRedhat3Cockpit FedoraVirtualizationJun 17, 2026 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted request with an invalid...Show more |
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Se...Show more |
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2...Show more |
2Elastic Redhat2Kibana Openshift Container PlatformJun 17, 2026 Mar 25, 2019 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascrip...Show more |