← Back

Redhat

redhat

5,674 CVEs • 537 products

Products (537)

Click to collapse
Toggle
Linux
linux
Satellite
satellite
Openstack
openstack
Openshift
openshift
Keycloak
keycloak
Fedora Core
fedora_core
Libvirt
libvirt
Ansible Tower
ansible_tower
Cloudforms
cloudforms
Ansible
ansible
Ceph Storage
ceph_storage
Linux Desktop
linux_desktop
Linux Server
linux_server
Jboss Fuse
jboss_fuse
Undertow
undertow
Storage
storage
Quay
quay
Fuse
fuse
Data Grid
data_grid
Resteasy
resteasy
Wildfly
wildfly
Jboss A Mq
jboss_a-mq
Ceph
ceph

CVEs (5,674)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Aug 26, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets t...Show more
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.Show less
1Redhat
1Openshift Serverless
Nov 21, 2024
Aug 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0...Show more
It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA for Serverless 1.16.0 and Serverless client kn 1.16.0. These have been fixed with Serverless 1.17.0.Show less
1Redhat
1Jboss Core Services Httpd
Nov 21, 2024
Aug 26, 2022
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to ac...Show more
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
5Debian
FedoraprojectIbm+2 more
23Build Of Quarkus
Codeready Linux BuilderDebian Linux+20 more
Nov 3, 2025
Aug 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
1Redhat
2Descision Manager
Wildfly
Nov 21, 2024
Aug 26, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially a...Show more
A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contains multiple expressions, a user who was granted access to the management interface can potentially access a vault expression they should not be able to access and possibly retrieve the item which was stored in the vault. The highest threat from this vulnerability is data confidentiality and integrity.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Aug 26, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
3Debian
OpenstackRedhat
3Debian Linux
KeystoneOpenstack Platform
Nov 21, 2024
Aug 26, 2022
N/A· v4
7.4 HIGH· v3
N/A· v2
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat fr...Show more
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
1Redhat
1Satellite
Nov 21, 2024
Aug 26, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerab...Show more
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data confidentiality.Show less
2Redhat
Rpm
2Enterprise Linux
Rpm
Nov 21, 2024
Aug 26, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directo...Show more
It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the parent directory of the file to be created. A local unprivileged user who owns another ancestor directory could potentially use this flaw to gain root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
1Redhat
4Ansible Automation Platform
Ansible Automation Platform Early AccessAnsible Automation Platform Text Only Advisories+1 more
Nov 21, 2024
Aug 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the iso...Show more
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevate the privilege from a low privileged user to an AWX user from outside the isolated environment.Show less
2Fedoraproject
Redhat
7Ceph Storage
Ceph Storage For Ibm Z SystemsCeph Storage For Power+4 more
Nov 3, 2025
Aug 25, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited...Show more
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.Show less
1Redhat
3Build Of Quarkus
Openshift Application RuntimesSmallrye Health
Nov 21, 2024
Aug 25, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
3Fedoraproject
RedhatRpm
3Enterprise Linux
FedoraRpm
Nov 21, 2024
Aug 25, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic...Show more
A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing a file. A local unprivileged user could use this flaw to exchange the original file with a symbolic link to a security-critical file and escalate their privileges on the system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
3Fedoraproject
RedhatRpm
3Enterprise Linux
FedoraRpm
Nov 21, 2024
Aug 25, 2022
N/A· v4
6.4 MEDIUM· v3
N/A· v2
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges...Show more
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Show less
3Debian
RedhatVirglrenderer Project
3Debian Linux
Enterprise LinuxVirglrenderer
Nov 21, 2024
Aug 25, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, lea...Show more
An out-of-bounds write issue was found in the VirGL virtual OpenGL renderer (virglrenderer). This flaw allows a malicious guest to create a specially crafted virgil resource and then issue a VIRTGPU_EXECBUFFER ioctl, leading to a denial of service or possible code execution.Show less
3Fedoraproject
RedhatUnzip Project
3Enterprise Linux
FedoraUnzip
Nov 21, 2024
Aug 24, 2022
N/A· v4
3.3 LOW· v3
N/A· v2
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading t...Show more
A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.Show less
3Debian
DogtagpkiRedhat
3Debian Linux
Enterprise LinuxNetwork Security Services For Java
Nov 21, 2024
Aug 24, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an...Show more
A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service.Show less
3Gnu
NetappRedhat
5Active Iq Unified Manager
Enterprise LinuxGnutls+2 more
Nov 21, 2024
Aug 24, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authen...Show more
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.Show less
4Debian
LinuxNetapp+1 more
8Debian Linux
Enterprise LinuxH300s Firmware+5 more
Nov 21, 2024
Aug 24, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal informat...Show more
An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information.Show less
4Debian
NetappPython+1 more
5Debian Linux
Enterprise LinuxOntap Select Deploy Administration Utility+2 more
Dec 17, 2025
Aug 24, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an a...Show more
A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.Show less