Skip to main content

Vendor archive

redhat CVEs

Beta · best-effort

5,982 CVEs tagged to vendor redhat666 Critical, 2,012 High, 2,837 Medium, 467 Low, 0 Unrated.

CVE-2024-3622

Published Apr 25, 2024

A flaw was found when using mirror-registry to install Quay. It uses a default secret, which is stored in plain-text format in one of the configuration template files. This issue…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3508

Published Apr 25, 2024

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6787

Published Apr 25, 2024

A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-3567

Published Apr 10, 2024

A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fra…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6725

Published Mar 15, 2024

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1725

Published Mar 7, 2024

A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the roo…

CVSS 6.5 · Medium

CVE-2024-1722

Published Feb 29, 2024

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-0560

Published Feb 28, 2024

A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection poli…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1635

Published Feb 19, 2024

A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection…

CVSS 7.5 · High

CVE-2023-50868

Published Feb 14, 2024

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Showing 426-450 of 5,982 CVEsPage 18 of 240