Vulnerabilities > Redhat > Service Interconnect

DATE CVE VULNERABILITY TITLE RISK
2023-12-18 CVE-2023-5056 Missing Authorization vulnerability in Redhat Service Interconnect 1.0
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster.
low complexity
redhat CWE-862
4.1
2023-10-10 CVE-2023-44487 Resource Exhaustion vulnerability in multiple products
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
7.5