Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-11-24 CVE-2020-10763 Information Exposure Through Log Files vulnerability in multiple products
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information.
local
low complexity
heketi-project redhat CWE-532
5.5
2020-11-24 CVE-2020-10762 Information Exposure Through Log Files vulnerability in Redhat Gluster-Block
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations.
local
low complexity
redhat CWE-532
5.5
2020-11-17 CVE-2020-10776 Cross-site Scripting vulnerability in Redhat Keycloak
A flaw was found in Keycloak before version 12.0.0, where it is possible to add unsafe schemes for the redirect_uri parameter.
network
low complexity
redhat CWE-79
4.8
2020-11-12 CVE-2020-25658 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.
network
high complexity
python-rsa-project redhat fedoraproject
5.9
2020-11-09 CVE-2020-25655 Incorrect Authorization vulnerability in Redhat Advanced Cluster Management for Kubernetes 2.0
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions.
network
low complexity
redhat CWE-863
6.5
2020-11-05 CVE-2020-25662 Unspecified vulnerability in Redhat Enterprise Linux 8.3
A Red Hat only CVE-2020-12352 regression issue was found in the way the Linux kernel's Bluetooth stack implementation handled the initialization of stack memory when handling certain AMP packets.
low complexity
redhat
6.5
2020-11-02 CVE-2020-25689 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller.
network
low complexity
redhat netapp
6.5
2020-10-16 CVE-2020-14299 Improper Authentication vulnerability in Redhat products
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode.
network
low complexity
redhat CWE-287
6.5
2020-10-07 CVE-2020-14355 Classic Buffer Overflow vulnerability in multiple products
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1.
6.6
2020-10-06 CVE-2020-25637 A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain.
local
low complexity
redhat opensuse
6.7