Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-08-23 CVE-2021-3827 Improper Authentication vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed.
network
high complexity
redhat CWE-287
6.8
2022-08-22 CVE-2021-3442 Unspecified vulnerability in Redhat Openshift API Management 2.9.1
A flaw was found in the Red Hat OpenShift API Management product.
network
low complexity
redhat
5.4
2022-08-22 CVE-2021-3659 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection.
local
low complexity
linux fedoraproject redhat CWE-476
5.5
2022-08-22 CVE-2022-2873 Incorrect Calculation of Buffer Size vulnerability in multiple products
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data.
5.5
2022-08-18 CVE-2022-2568 Improper Privilege Management vulnerability in Redhat Ansible Automation Platform 2.0/2.1/2.2
A privilege escalation flaw was found in the Ansible Automation Platform.
network
low complexity
redhat CWE-269
6.5
2022-08-16 CVE-2020-14379 XXE vulnerability in Redhat Jboss A-Mq 7
A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and information disclosure.
local
low complexity
redhat CWE-611
5.6
2022-07-25 CVE-2022-35651 Cross-site Scripting vulnerability in multiple products
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details.
network
low complexity
moodle redhat fedoraproject CWE-79
6.1
2022-07-25 CVE-2022-35653 Cross-site Scripting vulnerability in multiple products
A reflected XSS issue was identified in the LTI module of Moodle.
network
low complexity
moodle fedoraproject redhat CWE-79
6.1
2022-07-22 CVE-2022-1655 Incorrect Permission Assignment for Critical Resource vulnerability in Redhat Openstack 16.2
An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack.
network
low complexity
redhat CWE-732
6.5
2022-07-14 CVE-2022-2393 A flaw was found in pki-core, which could allow a user to get a certificate for another user identity when directory-based authentication is enabled.
low complexity
pki-core-project redhat
5.7