CVE-2020-15705
- EPSS 0.03%
- Veröffentlicht 29.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:03
GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB imag...
CVE-2020-15706
- EPSS 0.06%
- Veröffentlicht 29.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:03
GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure b...
CVE-2020-15707
- EPSS 0.04%
- Veröffentlicht 29.07.2020 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:06:04
Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffe...
CVE-2020-14298
- EPSS 0.14%
- Veröffentlicht 13.07.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:02:57
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malic...
CVE-2020-10752
- EPSS 0.37%
- Veröffentlicht 12.06.2020 23:15:10
- Zuletzt bearbeitet 21.11.2024 04:55:59
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server panic occurred. This flaw allows an attacker with the ability to cause an API Server error to read the ...
CVE-2020-7013
- EPSS 1.14%
- Veröffentlicht 03.06.2020 18:15:22
- Zuletzt bearbeitet 21.11.2024 05:36:29
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could possibly lead t...
- EPSS 3.6%
- Veröffentlicht 03.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:59
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending...
CVE-2020-10706
- EPSS 0.02%
- Veröffentlicht 12.05.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:53
A flaw was found in OpenShift Container Platform where OAuth tokens are not encrypted when the encryption of data at rest is enabled. This flaw allows an attacker with access to a backup to obtain OAuth tokens and then use them to log into the cluste...
CVE-2020-1741
- EPSS 0.24%
- Veröffentlicht 24.04.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:17
A flaw was found in openshift-ansible. OpenShift Container Platform (OCP) 3.11 is too permissive in the way it specified CORS allowed origins during installation. An attacker, able to man-in-the-middle the connection between the user's browser and th...
CVE-2020-1760
- EPSS 0.29%
- Veröffentlicht 23.04.2020 15:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:19
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.