Redhat
redhat
5,674 CVEs • 537 products
Products (537)
Click to collapseToggle
Products (537)
Click to collapse
CVEs (5,674)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Apr 13, 2022 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A use-after-free vulnerability was found in drm_lease_held in drivers/gpu/drm/drm_lease.c in the Linux kernel due to a race problem. This flaw allows a local user privilege attacker to cause a denial of service (DoS) or...Show more |
1Redhat 1Origin Aggregated Logging Nov 21, 2024 Apr 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the original fix for the netty-codec-http CVE-2021-21409, where the OpenShift Logging openshift-logging/elasticsearch6-rhel8 container was incomplete. The vulnerable netty-codec-http maven package was...Show more |
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. |
4Fedoraproject LinuxNetapp+1 more15Active Iq Unified Manager Enterprise LinuxFedora+12 moreNov 21, 2024 Apr 8, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. |
3Buildah Project FedoraprojectRedhat3Buildah Enterprise LinuxFedoraNov 21, 2024 Apr 4, 2022 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux...Show more |
3Crun Project FedoraprojectRedhat4Crun Enterprise LinuxFedora+1 moreNov 21, 2024 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritabl...Show more |
3Fedoraproject Podman ProjectRedhat14Developer Tools Enterprise LinuxEnterprise Linux Eus+11 moreNov 21, 2024 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheri...Show more |
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name]. |
1Redhat 2Openshift Container Platform Openshift Machine Config OperatorNov 21, 2024 Apr 1, 2022 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition c...Show more |
1Redhat 3Business Central Descision ManagerProcess AutomationNov 21, 2024 Apr 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was observed that while login into Business-central console, HTTP request discloses sensitive information like username and password when intercepted using some tool like burp suite etc. |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Mar 30, 2022 N/A· v4 3.4 LOW· v3 3.6 LOW· v2 A flaw was found in the Linux kernels implementation of audit rules, where a syscall can unexpectedly not be correctly not be logged by the audit subsystem |
5Canonical FedoraprojectLinux+2 more12Enterprise Linux FedoraH300e Firmware+9 moreNov 21, 2024 Mar 29, 2022 8.6 HIGH· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f...Show more |
2Netapp Redhat2Libvirt Ontap Select Deploy Administration UtilityNov 21, 2024 Mar 25, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in the libvirt nwfilter driver. The virNWFilterObjListNumOfNWFilters method failed to acquire the driver->nwfilters mutex before iterating over virNWFilterObj instances. There was no protection to stop a...Show more |
A flaw was found in all versions of kubeclient up to (but not including) v4.9.3, the Ruby client for Kubernetes REST API, in the way it parsed kubeconfig files. When the kubeconfig file does not configure custom CA to ve...Show more |
5Fedoraproject LinuxNetapp+2 more30Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+27 moreNov 21, 2024 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw a...Show more |
4Fedoraproject LinuxNetapp+1 more383scale Api Management Codeready Linux BuilderCodeready Linux Builder Eus+35 moreNov 21, 2024 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more |
3Fedoraproject NetappRedhat3Fedora LibvirtOntap Select Deploy Administration UtilityNov 21, 2024 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. |
4Debian FedoraprojectOpenexr+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not...Show more |
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session auth instead. This conceivably bypasses access controls and permits unauthorized information disclosure...Show more |
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak. |