CVE-2022-2990
- EPSS 0.13%
- Veröffentlicht 13.09.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:02:02
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups a...
CVE-2022-1677
- EPSS 0.23%
- Veröffentlicht 01.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 06:41:14
In OpenShift Container Platform, a user with permissions to create or modify Routes can craft a payload that inserts a malformed entry into one of the cluster router's HAProxy configuration files. This malformed entry can match any arbitrary hostname...
CVE-2022-1632
- EPSS 0.16%
- Veröffentlicht 01.09.2022 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:41:08
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an i...
CVE-2022-2132
- EPSS 0.69%
- Veröffentlicht 31.08.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:00:23
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
CVE-2022-0669
- EPSS 0.13%
- Veröffentlicht 29.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:39:08
A flaw was found in dpdk. This flaw allows a malicious vhost-user master to attach an unexpected number of fds as ancillary data to VHOST_USER_GET_INFLIGHT_FD / VHOST_USER_SET_INFLIGHT_FD messages that are not closed by the vhost-user slave. By sendi...
CVE-2022-0718
- EPSS 0.71%
- Veröffentlicht 29.08.2022 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:39:15
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
CVE-2021-3669
- EPSS 0.02%
- Veröffentlicht 26.08.2022 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:50
A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segment counts which could lead to resource exhaustion and DoS.
CVE-2021-3827
- EPSS 0.22%
- Veröffentlicht 23.08.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:22:33
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authoriza...
CVE-2020-27836
- EPSS 0.72%
- Veröffentlicht 22.08.2022 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:21:54
A flaw was found in cluster-ingress-operator. A change to how the router-default service allows only certain IP source ranges could allow an attacker to access resources that would otherwise be restricted to specified IP ranges. The highest threat fr...
CVE-2021-3695
- EPSS 0.06%
- Veröffentlicht 06.07.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:22:10
A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue ha...