Vulnerabilities > Redhat > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-20 CVE-2022-3596 Unspecified vulnerability in Redhat Openstack Platform 13.0
An information leak was found in OpenStack's undercloud.
network
low complexity
redhat
7.5
2023-09-20 CVE-2023-4853 Incorrect Authorization vulnerability in multiple products
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions.
network
high complexity
quarkus redhat CWE-863
8.1
2023-09-15 CVE-2022-3261 Cleartext Transmission of Sensitive Information vulnerability in Redhat Openstack Platform 16.2
A flaw was found in OpenStack.
network
low complexity
redhat CWE-319
7.5
2023-09-15 CVE-2023-0813 Improper Authentication vulnerability in Redhat Network Observability 1.0
A flaw was found in the Network Observability plugin for OpenShift console.
network
low complexity
redhat CWE-287
7.5
2023-09-14 CVE-2023-1108 Infinite Loop vulnerability in multiple products
A flaw was found in undertow.
network
low complexity
redhat netapp CWE-835
7.5
2023-09-13 CVE-2023-2680 Use After Free vulnerability in multiple products
This CVE exists because of an incomplete fix for CVE-2021-3750.
local
low complexity
qemu redhat CWE-416
8.2
2023-09-12 CVE-2023-4918 Cleartext Transmission of Sensitive Information vulnerability in Redhat Keycloak 22.0.2
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile.
network
low complexity
redhat CWE-319
8.8
2023-09-11 CVE-2022-1415 Deserialization of Untrusted Data vulnerability in Redhat products
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data.
network
low complexity
redhat CWE-502
8.8
2023-08-23 CVE-2023-3899 Incorrect Authorization vulnerability in multiple products
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization.
local
low complexity
redhat fedoraproject CWE-863
7.8
2023-08-16 CVE-2023-4387 Use After Free vulnerability in multiple products
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel.
local
low complexity
linux redhat CWE-416
7.1