Redhat
redhat
5,899 CVEs • 544 products
Products (544)
Click to collapseToggle
Products (544)
Click to collapse
CVEs (5,899)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Openshift Container Platform Jun 17, 2026 Oct 5, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A content spoofing flaw was found in OpenShift's OAuth endpoint. This flaw allows a remote, unauthenticated attacker to inject text into a webpage, enabling the obfuscation of a phishing operation. |
3Fedoraproject LibtiffRedhat3Enterprise Linux FedoraLibtiffJun 23, 2026 Oct 4, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this mem...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 4, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. T...Show more |
1Redhat 3Ansible Automation Platform Ansible DeveloperAnsible InsideJun 17, 2026 Oct 4, 2023 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. This flaw allows an attacker to retrieve the credentials from the log, r...Show more |
1Redhat 2Ansible Automation Platform Ansible CollectionJun 17, 2026 Oct 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the private key directly to the standard output. This flaw allows an attacker to fetch those keys from the l...Show more |
1Redhat 4Ansible Automation Controller Ansible Automation PlatformAnsible Developer+1 moreJun 17, 2026 Oct 4, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. |
2Candlepinproject Redhat2Candlepin SatelliteJun 17, 2026 Oct 4, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant. |
2Opendatahub Redhat2Open Data Hub Dashboard Openshift Data ScienceJun 17, 2026 Oct 4, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Red Hat OpenShift Data Science. When exporting a pipeline from the Elyra notebook pipeline editor as Python DSL or YAML, it reads S3 credentials from the cluster (ds pipeline server) and saves them in...Show more |
2Ovn Redhat3Fast Datapath Open Virtual NetworkOpenshift Container PlatformJun 17, 2026 Oct 4, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properl...Show more |
2Dogtagpki Redhat2Enterprise Linux Network Security Services For JavaJun 17, 2026 Oct 4, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page). |
A vulnerability was found in the Hot Rod client. This security issue occurs as the Hot Rod client does not enable hostname validation when using TLS, possibly resulting in a man-in-the-middle (MITM) attack. |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Oct 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can a...Show more |
7Canonical DebianFedoraproject+4 more39Bootstrap Os Codeready Linux BuilderCodeready Linux Builder Eus+36 moreJun 17, 2026 Oct 3, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES env...Show more |
2Linux Redhat10Codeready Linux Builder Codeready Linux Builder For Arm64Codeready Linux Builder For Power Little Endian+7 moreJun 17, 2026 Oct 3, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencin...Show more |
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding. |
8Apple DebianFedoraproject+5 more11Chrome Debian LinuxEdge+8 moreJun 17, 2026 Sep 28, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security sever...Show more |
A flaw was found in libnbd. A server can reply with a block size larger than 2^63 (the NBD spec states the size is a 64-bit unsigned value). This issue could lead to an application crash or other unintended behavior for...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 28, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue m...Show more |
1Redhat 3Jboss A Mq Jboss MiddlewareOpenshift Container PlatformJun 17, 2026 Sep 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in Red Hat's AMQ Broker, which stores certain passwords in a secret security-properties-prop-module, defined in ActivemqArtemisSecurity CR; however, they are shown in plaintext in the StatefulSet details...Show more |