Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2020-05-08 CVE-2019-10170 Unspecified vulnerability in Redhat Keycloak
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy.
network
low complexity
redhat
7.2
2020-05-08 CVE-2019-10169 Unspecified vulnerability in Redhat Keycloak
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy.
network
low complexity
redhat
7.2
2020-05-06 CVE-2020-10693 A flaw was found in Hibernate Validator version 6.1.2.Final.
network
low complexity
redhat ibm quarkus oracle
5.3
2020-05-04 CVE-2020-10686 Unspecified vulnerability in Redhat Keycloak 8.0.2/9.0.0
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself.
network
low complexity
redhat
4.7
2020-05-04 CVE-2020-1732 Improper Input Validation vulnerability in Redhat products
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
network
high complexity
redhat CWE-20
4.2
2020-04-30 CVE-2020-10691 Path Traversal vulnerability in Redhat Ansible Engine and Ansible Tower
An archive traversal flaw was found in all ansible-engine versions 2.9.x prior to 2.9.7, when running ansible-galaxy collection install.
local
low complexity
redhat CWE-22
5.2
2020-04-29 CVE-2020-12458 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
An information-disclosure flaw was found in Grafana through 6.7.3.
local
low complexity
grafana redhat fedoraproject CWE-732
5.5
2020-04-28 CVE-2020-12430 Memory Leak vulnerability in Redhat Enterprise Linux and Libvirt
An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0.
network
low complexity
redhat CWE-401
6.5
2020-04-28 CVE-2020-1745 Unspecified vulnerability in Redhat Undertow
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final.
network
low complexity
redhat
critical
9.8
2020-04-27 CVE-2020-1762 Session Fixation vulnerability in multiple products
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT cookie and using that to spoof a user session, possibly gaining privileges to view and alter the Istio configuration.
network
low complexity
kiali redhat CWE-384
8.6