Vulnerabilities > Redhat > High

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-3412 Unspecified vulnerability in Redhat 3Scale and 3Scale API Management
It was found that all versions of 3Scale developer portal lacked brute force protections.
network
low complexity
redhat
7.3
2021-06-01 CVE-2021-3495 An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7.
network
low complexity
netlify redhat
8.8
2021-06-01 CVE-2021-3516 Use After Free vulnerability in multiple products
There's a flaw in libxml2's xmllint in versions before 2.9.11.
7.8
2021-05-28 CVE-2021-20267 A flaw was found in openstack-neutron's default Open vSwitch firewall rules.
network
low complexity
openstack redhat
7.1
2021-05-28 CVE-2020-25710 A flaw was found in OpenLDAP in versions before 2.4.56.
network
low complexity
openldap redhat debian fedoraproject
7.5
2021-05-27 CVE-2020-10709 Insufficient Session Expiration vulnerability in Redhat Ansible Tower
A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application.
local
low complexity
redhat CWE-613
7.1
2021-05-27 CVE-2021-30500 Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0.
local
low complexity
upx-project redhat fedoraproject
7.8
2021-05-26 CVE-2020-10695 Unspecified vulnerability in Redhat Single Sign-On
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container.
local
low complexity
redhat
7.8
2021-05-26 CVE-2018-10863 Files or Directories Accessible to External Parties vulnerability in Redhat Certification 7.0
It was discovered that redhat-certification 7 is not properly configured and it lists all files and directories in the /var/www/rhcert/store/transfer directory, through the /rhcert-transfer URL.
network
low complexity
redhat CWE-552
7.5
2021-05-26 CVE-2018-10865 Missing Authorization vulnerability in Redhat Certification 7.0
It was discovered that the /configuration view of redhat-certification 7 does not perform an authorization check and it allows an unauthenticated user to call a "restart" RPC method on any host accessible by the system, even if not belonging to him.
network
low complexity
redhat CWE-862
7.5