Skip to main content

Vendor archive

redhat CVEs

Beta · best-effort

5,982 CVEs tagged to vendor redhat666 Critical, 2,012 High, 2,837 Medium, 467 Low, 0 Unrated.

CVE-2022-3916

Published Sep 20, 2023

A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root ses…

CVSS 6.8 · Medium

CVE-2023-0462

Published Sep 20, 2023

An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1438

Published Sep 20, 2023

A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3261

Published Sep 15, 2023

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive i…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4959

Published Sep 15, 2023

A flaw was found in Quay. Cross-site request forgery (CSRF) attacks force a user to perform unwanted actions in an application. During the pentest, it was detected that the config…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3301

Published Sep 13, 2023

A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A m…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2680

Published Sep 13, 2023

This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4918

Published Sep 12, 2023

A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm"…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-0119

Published Sep 12, 2023

A stored Cross-site scripting vulnerability was found in foreman. The Comment section in the Hosts tab has incorrect filtering of user input data. As a result of the attack, an at…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-38201

Published Aug 25, 2023

A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate a…

CVSS 6.5 · Medium

CVE-2023-4042

Published Aug 23, 2023

A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghos…

CVSS 5.5 · Medium
Showing 651-675 of 5,982 CVEsPage 27 of 240