CVE-2022-0718
- EPSS 0.35%
- Veröffentlicht 29.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:39:15
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVE-2021-3669
- EPSS 0.02%
- Veröffentlicht 26.08.2022 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:50
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2021-3827
- EPSS 0.21%
- Veröffentlicht 23.08.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:22:33
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authoriza...
CVE-2020-27836
- EPSS 0.72%
- Veröffentlicht 22.08.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:54
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat fr...
CVE-2021-3695
- EPSS 0.06%
- Veröffentlicht 06.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:10
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...
CVE-2021-3696
- EPSS 0.11%
- Veröffentlicht 06.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:10
A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an atta...
- EPSS 0.07%
- Veröffentlicht 06.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:10
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a...
CVE-2022-1708
- EPSS 0.59%
- Veröffentlicht 07.06.2022 18:15:11
- Zuletzt bearbeitet 21.11.2024 06:41:17
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O...
CVE-2022-1706
- EPSS 0.59%
- Veröffentlicht 17.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:17
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threa...
CVE-2022-1227
- EPSS 33.72%
- Veröffentlicht 29.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:17
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' co...