Redhat
redhat
5,768 CVEs • 542 products
Products (542)
Click to collapseToggle
Products (542)
Click to collapse
CVEs (5,768)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGawkJun 17, 2026 Sep 25, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information. |
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash. |
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespac...Show more |
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. |
2Openstack Redhat2Heat Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impac...Show more |
2Kubernetes Redhat2Kube Apiserver Openshift Container PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 An authentication bypass vulnerability was discovered in kube-apiserver. This issue could allow a remote, authenticated attacker who has been given permissions "update, patch" the "pods/ephemeralcontainers" subresource b...Show more |
2Kiali Redhat2Kiali Openshift Service MeshJun 17, 2026 Sep 23, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbit...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Ibm ZOpenshift Container Platform For Linuxone+2 moreJun 17, 2026 Sep 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code...Show more |
2Redhat Theforeman2Foreman SatelliteJun 17, 2026 Sep 22, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora CoreOS configurations in templates, poss...Show more |
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising p...Show more |
1Redhat 6Keycloak Openshift Container PlatformOpenshift Container Platform For Linuxone+3 moreJun 17, 2026 Sep 20, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more |
2Redhat Theforeman2Foreman SatelliteJun 17, 2026 Sep 20, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload. |
2Redhat Theforeman2Foreman SatelliteJun 17, 2026 Sep 20, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating system. |
A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability. |
2Quarkus Redhat12Build Of Optaplanner Build Of QuarkusDecision Manager+9 moreJun 17, 2026 Sep 20, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an at...Show more |
3Fedoraproject GnuRedhat22Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+19 moreJul 14, 2026 Sep 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module imp...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreJun 17, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
A flaw was found in the Kubernetes service for notebooks in RHODS, where it does not prevent pods from other namespaces and applications from making requests to the Jupyter API. This flaw can lead to file content exposur...Show more |
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki authToken configuration is set to FORWARD mode, authentication is no longer enforced, allowing any user who can connect to the O...Show more |
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. |