Skip to main content

Vendor/product archive

redhat / openshift_container_platform_for_ibm_z CVEs

Beta · best-effort

9 CVEs tagged to redhat / openshift_container_platform_for_ibm_z0 Critical, 5 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2024-8883

Published Sep 19, 2024

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http:…

CVSS 6.1 · Medium
evidence mentions
17
Buzz score
36.9

CVE-2024-1132

Published Apr 17, 2024

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass valida…

CVSS 8.1 · High
evidence mentions
14
Buzz score
33.6

CVE-2024-1725

Published Mar 7, 2024

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the roo…

CVSS 6.5 · Medium

CVE-2023-6291

Published Jan 26, 2024

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access t…

CVSS 7.1 · High

CVE-2023-2585

Published Dec 21, 2023

Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent re…

CVSS 3.5 · Low

CVE-2022-4039

Published Sep 22, 2023

A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use…

CVSS 8.0 · High

CVE-2020-8945

Published Feb 12, 2020

The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or po…

CVSS 7.5 · High
Showing 1-9 of 9 CVEsPage 1 of 1