Vulnerabilities > Redhat > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-09-16 CVE-2020-1694 Incorrect Permission Assignment for Critical Resource vulnerability in Redhat Keycloak
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience.
network
low complexity
redhat CWE-732
4.9
2020-09-16 CVE-2020-14348 Improper Check for Unusual or Exceptional Conditions vulnerability in Redhat AMQ Online
It was found in AMQ Online before 1.5.2 that injecting an invalid field to a user's AddressSpace configuration of the user namespace puts AMQ Online in an inconsistent state, where the AMQ Online components do not operate properly, such as the failure of provisioning and the failure of creating addresses, though this does not impact upon already existing messaging clients or brokers.
network
low complexity
redhat CWE-754
4.3
2020-09-16 CVE-2020-10748 Cross-site Scripting vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances.
network
low complexity
redhat CWE-79
6.1
2020-09-16 CVE-2020-10715 Improper Input Validation vulnerability in Redhat Openshift
A content spoofing vulnerability was found in the openshift/console 3.11 and 4.x.
network
low complexity
redhat CWE-20
4.3
2020-09-16 CVE-2020-1710 Unspecified vulnerability in Redhat products
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
network
low complexity
redhat
5.3
2020-09-15 CVE-2020-14331 Out-of-bounds Write vulnerability in multiple products
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console, calling an ioctl VT_RESIZE, which causes an out-of-bounds write to occur.
low complexity
linux redhat CWE-787
6.6
2020-09-15 CVE-2020-10759 Unspecified vulnerability in Redhat Enterprise Linux 7.0/8.0
A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware.
local
low complexity
redhat
6.0
2020-09-11 CVE-2020-14332 Improper Output Neutralization for Logs vulnerability in multiple products
A flaw was found in the Ansible Engine when using module_args.
local
low complexity
redhat debian CWE-117
5.5
2020-09-11 CVE-2020-14330 Information Exposure Through Log Files vulnerability in multiple products
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output.
local
low complexity
redhat debian CWE-532
5.5
2020-09-03 CVE-2020-14373 Use After Free vulnerability in multiple products
A use after free was found in igc_reloc_struct_ptr() of psi/igc.c of ghostscript-9.25.
local
low complexity
artifex redhat CWE-416
5.5