Vulnerabilities > Redhat > High

DATE CVE VULNERABILITY TITLE RISK
2021-03-24 CVE-2019-19353 Unspecified vulnerability in Redhat Openshift Container Platform 4.0
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/hive as shipped in Red Hat Openshift 4.
local
high complexity
redhat
7.0
2021-03-24 CVE-2019-19352 Unspecified vulnerability in Redhat Openshift Container Platform 4.0
An insecure modification vulnerability in the /etc/passwd file was found in the operator-framework/presto as shipped in Red Hat Openshift 4.
local
high complexity
redhat
7.0
2021-03-24 CVE-2019-19350 Unspecified vulnerability in Redhat Openshift 3.11/4.0
An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible-service-broker as shipped in Red Hat Openshift 4 and 3.11.
local
low complexity
redhat
7.8
2021-03-24 CVE-2019-19349 Unspecified vulnerability in Redhat Openshift 4.0
An insecure modification vulnerability in the /etc/passwd file was found in the container operator-framework/operator-metering as shipped in Red Hat Openshift 4.
local
low complexity
redhat
7.8
2021-03-23 CVE-2019-19343 Improper Resource Shutdown or Release vulnerability in multiple products
A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4.
network
low complexity
redhat netapp CWE-404
7.5
2021-03-23 CVE-2021-20270 Infinite Loop vulnerability in multiple products
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
network
low complexity
pygments redhat fedoraproject debian CWE-835
7.5
2021-03-23 CVE-2021-20222 Cross-site Scripting vulnerability in Redhat Keycloak
A flaw was found in keycloak.
network
high complexity
redhat CWE-79
7.5
2021-03-19 CVE-2019-10200 Unspecified vulnerability in Redhat Openshift Container Platform 4.0
A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedule workloads on master nodes.
network
low complexity
redhat
7.2
2021-03-18 CVE-2019-14852 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Redhat 3Scale API Management 2.0
A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol.
network
low complexity
redhat CWE-327
7.5
2021-03-18 CVE-2020-27827 A flaw was found in multiple versions of OpenvSwitch. 7.5