Vulnerabilities > Redhat

DATE CVE VULNERABILITY TITLE RISK
2022-09-01 CVE-2022-1677 Unspecified vulnerability in Redhat Openshift Container Platform
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files.
network
low complexity
redhat
6.3
2022-09-01 CVE-2022-1902 Unspecified vulnerability in Redhat Advanced Cluster Security 3.68/3.69/3.70
A flaw was found in the Red Hat Advanced Cluster Security for Kubernetes.
network
low complexity
redhat
8.8
2022-09-01 CVE-2022-23452 An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container.
network
low complexity
openstack redhat
4.9
2022-09-01 CVE-2022-2238 Unspecified vulnerability in Redhat Advanced Cluster Management for Kubernetes 2.0
A vulnerability was found in the search-api container in Red Hat Advanced Cluster Management for Kubernetes when a query in the search filter gets parsed by the backend.
network
low complexity
redhat
6.5
2022-09-01 CVE-2022-2256 Cross-site Scripting vulnerability in Redhat Single Sign-On 7.0
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7.
network
low complexity
redhat CWE-79
3.8
2022-09-01 CVE-2022-2403 Unspecified vulnerability in Redhat Openshift 4.11/4.12/4.9
A credentials leak was found in the OpenShift Container Platform.
network
low complexity
redhat
6.5
2022-09-01 CVE-2022-2447 Operation on a Resource after Expiration or Release vulnerability in multiple products
A flaw was found in Keystone.
network
high complexity
openstack redhat CWE-672
6.6
2022-09-01 CVE-2022-2639 Incorrect Conversion between Numeric Types vulnerability in multiple products
An integer coercion error was found in the openvswitch kernel module.
local
low complexity
linux redhat CWE-681
7.8
2022-09-01 CVE-2022-2738 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117.
network
high complexity
redhat podman-project
7.5
2022-09-01 CVE-2022-2739 Cleartext Storage of Sensitive Information vulnerability in multiple products
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056.
network
high complexity
redhat podman-project CWE-312
5.3