Redhat
redhat
5,653 CVEs • 536 products
Products (536)
Click to collapseToggle
Products (536)
Click to collapse
CVEs (5,653)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Ansible Automation Platform Ansible CollectionNov 21, 2024 Oct 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the l...Show more |
1Redhat 4Ansible Automation Controller Ansible Automation PlatformAnsible Developer+1 moreNov 21, 2024 Oct 4, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. |
2Candlepinproject Redhat2Candlepin SatelliteNov 21, 2024 Oct 4, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant. |
2Opendatahub Redhat2Open Data Hub Dashboard Openshift Data ScienceNov 21, 2024 Oct 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in...Show more |
2Ovn Redhat3Fast Datapath Open Virtual NetworkOpenshift Container PlatformNov 21, 2024 Oct 4, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properl...Show more |
2Dogtagpki Redhat2Enterprise Linux Network Security Services For JavaNov 21, 2024 Oct 4, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page). |
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnNov 21, 2024 Oct 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can a...Show more |
7Canonical DebianFedoraproject+4 more39Bootstrap Os Codeready Linux BuilderCodeready Linux Builder Eus+36 moreMay 12, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env...Show more |
2Linux Redhat10Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Power Little Endian+7 moreNov 21, 2024 Oct 3, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencin...Show more |
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Sep 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. |
8Apple DebianFedoraproject+5 more11Chrome Debian LinuxEdge+8 moreOct 24, 2025 Sep 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...Show more |
A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Sep 28, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue m...Show more |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformNov 21, 2024 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details...Show more |
3Fedoraproject MariadbRedhat12Enterprise Linux Enterprise Linux EusEnterprise Linux For Arm 64+9 moreOct 1, 2025 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformNov 21, 2024 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access inf...Show more |
1Redhat 7Jboss Enterprise Application Platform Jboss Enterprise Application Platform Text Only AdvisoriesOpenshift Container Platform+4 moreNov 21, 2024 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If th...Show more |
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information disclosure flaw via an exception triggered by a header containing an illegal value. This issue could allow an a...Show more |