Vulnerabilities > Redhat > Satellite > High

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-4320 Insufficient Session Expiration vulnerability in Redhat Satellite
An arithmetic overflow flaw was found in Satellite when creating a new personal access token.
network
low complexity
redhat CWE-613
7.5
2023-10-10 CVE-2023-44487 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. 7.5
2023-10-04 CVE-2023-1832 Incorrect Authorization vulnerability in multiple products
An improper access control flaw was found in Candlepin.
network
low complexity
candlepinproject redhat CWE-863
8.1
2022-08-26 CVE-2021-3414 Improper Preservation of Permissions vulnerability in Redhat Satellite 6.7
A flaw was found in satellite.
network
low complexity
redhat CWE-281
8.1
2022-08-22 CVE-2021-3590 Cleartext Transmission of Sensitive Information vulnerability in multiple products
A flaw was found in Foreman project.
network
low complexity
theforeman redhat CWE-319
8.8
2022-03-23 CVE-2021-3589 Missing Authentication for Critical Function vulnerability in multiple products
An authorization flaw was found in Foreman Ansible.
network
high complexity
theforeman redhat CWE-306
8.0
2021-12-23 CVE-2021-3584 A server side remote code execution vulnerability was found in Foreman project.
network
low complexity
theforeman redhat
7.2
2021-12-08 CVE-2021-44420 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. 7.3
2021-06-02 CVE-2020-14380 Unspecified vulnerability in Redhat Satellite 6.7.2
An account takeover flaw was found in Red Hat Satellite 6.7.2 onward.
network
high complexity
redhat
7.5
2020-07-31 CVE-2020-14334 Unspecified vulnerability in Redhat Satellite 6.0
A flaw was found in Red Hat Satellite 6 which allows privileged attacker to read cache files.
local
low complexity
redhat
8.8