Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2022-09-06 CVE-2022-25310 NULL Pointer Dereference vulnerability in multiple products
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file.
local
low complexity
gnu redhat CWE-476
5.5
2022-09-01 CVE-2022-1632 An Improper Certificate Validation attack was found in Openshift.
network
low complexity
redhat fedoraproject
6.5
2022-09-01 CVE-2022-1677 Unspecified vulnerability in Redhat Openshift Container Platform
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files.
network
low complexity
redhat
6.3
2022-09-01 CVE-2022-1902 Unspecified vulnerability in Redhat Advanced Cluster Security 3.68/3.69/3.70
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes.
network
low complexity
redhat
8.8
2022-09-01 CVE-2022-23452 An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container.
network
low complexity
openstack redhat
4.9
2022-09-01 CVE-2022-2238 Unspecified vulnerability in Redhat Advanced Cluster Management for Kubernetes 2.0
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend.
network
low complexity
redhat
6.5
2022-09-01 CVE-2022-2256 Cross-site Scripting vulnerability in Redhat Single Sign-On 7.0
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7.
network
low complexity
redhat CWE-79
3.8
2022-09-01 CVE-2022-2403 Unspecified vulnerability in Redhat Openshift 4.11/4.12/4.9
A credentials leak was found in the OpenShift Container Platform.
network
low complexity
redhat
6.5
2022-09-01 CVE-2022-2447 Operation on a Resource after Expiration or Release vulnerability in multiple products
A flaw was found in Keystone.
network
high complexity
openstack redhat CWE-672
6.6
2022-09-01 CVE-2022-2639 Incorrect Conversion between Numeric Types vulnerability in multiple products
An integer coercion error was found in the openvswitch kernel module.
local
low complexity
linux redhat CWE-681
7.8