Redhat

Update Infrastructure

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 20.07.2026 14:18:18
  • Zuletzt bearbeitet 22.07.2026 19:16:54

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated ad...

Medienbericht
  • EPSS 4.02%
  • Veröffentlicht 17.06.2026 14:04:32
  • Zuletzt bearbeitet 11.08.2026 15:12:52

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_in...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 26.05.2026 16:16:07
  • Zuletzt bearbeitet 11.08.2026 10:17:12

A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validation. An attacker can provide a specially crafted `.solv` file, which, ...

Medienbericht
  • EPSS 9.96%
  • Veröffentlicht 22.05.2026 14:11:41
  • Zuletzt bearbeitet 11.08.2026 14:48:32

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression (PCRE) captures (for ex...

  • EPSS 0.31%
  • Veröffentlicht 20.05.2026 23:34:56
  • Zuletzt bearbeitet 31.07.2026 18:17:37

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. This leads to an undersized memory allocation and a ...

  • EPSS 0.41%
  • Veröffentlicht 20.05.2026 23:16:36
  • Zuletzt bearbeitet 31.07.2026 18:17:38

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could exploit this by providing malicious SHA384 or SHA51...

  • EPSS 1.12%
  • Veröffentlicht 05.02.2024 21:15:11
  • Zuletzt bearbeitet 24.03.2026 12:16:08

A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

  • EPSS 1.12%
  • Veröffentlicht 05.02.2024 21:15:10
  • Zuletzt bearbeitet 12.05.2026 11:16:16

A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 25.10.2022 18:15:10
  • Zuletzt bearbeitet 07.05.2025 20:15:21

The collection remote for pulp_ansible stores tokens in plaintext instead of using pulp's encrypted field and exposes them in read/write mode via the API () instead of marking it as write only.

Exploit
  • EPSS 0.26%
  • Veröffentlicht 04.11.2019 13:15:10
  • Zuletzt bearbeitet 21.11.2024 01:55:43

RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates