CVE-2024-9676
- EPSS 2.67%
- Veröffentlicht 15.10.2024 16:15:06
- Zuletzt bearbeitet 03.04.2025 02:15:19
A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image us...
CVE-2024-8883
- EPSS 4.89%
- Veröffentlicht 19.09.2024 16:15:06
- Zuletzt bearbeitet 26.11.2024 19:15:32
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes...
CVE-2024-4629
- EPSS 0.17%
- Veröffentlicht 03.09.2024 20:15:09
- Zuletzt bearbeitet 21.11.2024 09:43:14
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed...
CVE-2024-1132
- EPSS 0.24%
- Veröffentlicht 17.04.2024 14:15:07
- Zuletzt bearbeitet 30.06.2025 13:58:57
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain ...
CVE-2024-1725
- EPSS 0.14%
- Veröffentlicht 07.03.2024 20:15:50
- Zuletzt bearbeitet 26.03.2025 05:15:40
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent Volume that ...
CVE-2024-1635
- EPSS 8.33%
- Veröffentlicht 19.02.2024 22:15:48
- Zuletzt bearbeitet 07.05.2025 12:27:53
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immedia...
CVE-2023-6291
- EPSS 0.2%
- Veröffentlicht 26.01.2024 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:43:32
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate o...
CVE-2023-2585
- EPSS 0.11%
- Veröffentlicht 21.12.2023 10:15:34
- Zuletzt bearbeitet 21.11.2024 07:58:52
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malic...
CVE-2023-5625
- EPSS 0.08%
- Veröffentlicht 01.11.2023 14:15:38
- Zuletzt bearbeitet 06.12.2024 11:15:07
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
CVE-2022-4318
- EPSS 0.04%
- Veröffentlicht 25.09.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:35:01
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.