Vulnerabilities > Linuxfoundation > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-30 CVE-2020-13794 Information Exposure vulnerability in Linuxfoundation Harbor
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
network
low complexity
linuxfoundation CWE-200
4.0
2020-09-09 CVE-2020-15163 Insufficient Verification of Data Authenticity vulnerability in Linuxfoundation the Update Framework
Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time.
4.9
2020-08-31 CVE-2020-15687 Unspecified vulnerability in Linuxfoundation Acrn 1.6.1/2.0
Missing access control restrictions in the Hypervisor component of the ACRN Project (v2.0 and v1.6.1) allow a malicious entity, with root access in the Service VM userspace, to abuse the PCIe assign/de-assign Hypercalls via crafted ioctls and payloads.
network
low complexity
linuxfoundation
5.0
2020-07-15 CVE-2020-13788 Server-Side Request Forgery (SSRF) vulnerability in Linuxfoundation Harbor
Harbor prior to 2.0.1 allows SSRF with this limitation: an attacker with the ability to edit projects can scan ports of hosts accessible on the Harbor server's intranet.
network
low complexity
linuxfoundation CWE-918
4.0
2020-06-26 CVE-2020-10753 Injection vulnerability in multiple products
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway).
6.5
2020-06-19 CVE-2020-10750 Information Exposure Through Log Files vulnerability in Linuxfoundation Jaeger
Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used.
local
low complexity
linuxfoundation CWE-532
5.5
2020-06-11 CVE-2020-11090 Resource Exhaustion vulnerability in Linuxfoundation Indy-Node 1.12.2
In Indy Node 1.12.2, there is an Uncontrolled Resource Consumption vulnerability.
network
low complexity
linuxfoundation CWE-400
5.0
2020-06-03 CVE-2020-10749 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks.
network
high complexity
linuxfoundation redhat fedoraproject
6.0
2020-05-13 CVE-2020-12831 Incorrect Permission Assignment for Critical Resource vulnerability in Linuxfoundation Free Range Routing
An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1.
network
low complexity
linuxfoundation CWE-732
5.3
2020-04-23 CVE-2020-1760 Cross-site Scripting vulnerability in multiple products
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3.
6.1