Vulnerabilities
Vulnerable Software
Redhat:  Security Vulnerabilities
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
CVSS Score
4.8
EPSS Score
0.02
Published
2019-12-05
OpenShift haproxy cartridge: predictable /tmp in set-proxy connection hook which could facilitate DoS
CVSS Score
5.5
EPSS Score
0.003
Published
2019-12-05
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.
CVSS Score
9.3
EPSS Score
0.011
Published
2019-12-05
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
CVSS Score
9.3
EPSS Score
0.011
Published
2019-12-04
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the "Dragonblood" attack and CVE-2019-9494.
CVSS Score
6.5
EPSS Score
0.016
Published
2019-12-03
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
CVSS Score
9.8
EPSS Score
0.015
Published
2019-12-03
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
CVSS Score
4.7
EPSS Score
0.003
Published
2019-12-03
Katello has multiple XSS issues in various entities
CVSS Score
5.4
EPSS Score
0.006
Published
2019-12-03
OpenShift cartridge allows remote URL retrieval
CVSS Score
8.1
EPSS Score
0.01
Published
2019-12-03
A flaw was found in rhn-proxy. This vulnerability may allow the rhn-proxy to transmit user credentials in clear-text when it accesses RHN Satellite. This could lead to information disclosure, where sensitive authentication details are exposed to unauthorized parties.
CVSS Score
8.6
EPSS Score
0.01
Published
2019-12-02


Contact Us

Shodan ® - All rights reserved