Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-10742 Out-of-bounds Write vulnerability in multiple products
A flaw was found in the Linux kernel.
local
low complexity
linux redhat CWE-787
6.0
2021-06-02 CVE-2020-10743 It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests.
network
low complexity
elastic redhat
4.3
2021-06-01 CVE-2021-3425 Unspecified vulnerability in Redhat Jboss A-Mq 7
A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker application logfile when using the jdbc persistence functionality.
local
low complexity
redhat
4.4
2021-06-01 CVE-2021-3424 Unspecified vulnerability in Redhat Single Sign-On 7.4
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible.
network
low complexity
redhat
5.3
2021-06-01 CVE-2021-20306 Unspecified vulnerability in Redhat Descision Manager, Jbpm and Process Automation
A flaw was found in the BPMN editor in version jBPM 7.51.0.Final.
network
low complexity
redhat
4.3
2021-06-01 CVE-2021-3543 Use After Free vulnerability in multiple products
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor.
6.7
2021-05-28 CVE-2021-3514 Unspecified vulnerability in Redhat 389 Directory Server
When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a specially crafted query, causing a crash.
network
low complexity
redhat
6.5
2021-05-28 CVE-2020-1729 Incorrect Authorization vulnerability in Redhat Smallrye Config
A flaw was found in SmallRye's API through version 1.6.1.
local
low complexity
redhat CWE-863
4.4
2021-05-28 CVE-2020-27826 Unspecified vulnerability in Redhat Keycloak
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API.
network
high complexity
redhat
4.2
2021-05-28 CVE-2021-20201 A flaw was found in spice in versions before 0.14.92.
network
low complexity
spice-project redhat
5.3