Vulnerabilities > Redpanda
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-18 | CVE-2023-50976 | Missing Authorization vulnerability in Redpanda Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. | 9.8 |
2023-04-08 | CVE-2023-30450 | Unspecified vulnerability in Redpanda rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. | 4.3 |
2023-02-13 | CVE-2023-24619 | Insufficiently Protected Credentials vulnerability in Redpanda Redpanda before 22.3.12 discloses cleartext AWS credentials. | 5.5 |