Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

RED HAT — Vulnerabilities & Security Advisories 676

Browse all 676 CVE security advisories affecting RED HAT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

CVE IDTitleCVSSSeverityPublished
CVE-2025-5416 Keycloak-core: keycloak environment information — Red Hat Build of KeycloakCWE-497 2.7 Low2025-06-20
CVE-2025-6052 Glib: integer overflow in g_string_maybe_expand() leading to potential buffer overflow in glib gstring — Red Hat Enterprise Linux 10CWE-190 3.7 Low2025-06-13
CVE-2025-5024 Gnome-remote-desktop: uncontrolled resource consumption due to malformed rdp pdus — Red Hat Enterprise Linux 10CWE-400 7.4 High2025-05-22
CVE-2025-4035 Libsoup: cookie domain validation bypass via uppercase characters in libsoup — Red Hat Enterprise Linux 10CWE-178 4.3 Medium2025-04-29
CVE-2025-2157 Foreman: disclosure of executed commands and outputs in foreman / red hat satellite — Satellite ServerCWE-922 3.3 Low2025-03-15
CVE-2022-4975 Rhacs: cross-site scripting in portal — Red Hat Advanced Cluster Security 3CWE-79 8.9 High2025-01-27
CVE-2024-10451 Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process — Red Hat build of Keycloak 24CWE-798 5.9 Medium2024-11-25
CVE-2023-6110 Openstack: deleting a non existing access rule deletes another existing access rule in it's scope — Red Hat OpenStack Platform 17.1 for RHEL 8CWE-237 5.5 Medium2024-11-17
CVE-2023-4639 Undertow: cookie smuggling/spoofing — Migration Toolkit for Runtimes 1 on RHEL 8CWE-444 7.4 High2024-11-17
CVE-2023-1419 Debezium: script injection via connector parameter — Red Hat build of DebeziumCWE-233 5.9 Medium2024-11-17
CVE-2022-2232 Keycloak: ldap injection on username input — Red Hat Single Sign-On 7CWE-20 7.5 High2024-11-14
CVE-2023-1973 Undertow: unrestricted request storage leads to memory exhaustion — Red Hat JBoss Enterprise Application Platform 7CWE-20 7.5 High2024-11-07
CVE-2023-1932 Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss — A-MQ Clients 2 6.1 Medium2024-11-07
CVE-2024-50312 Graphql: information disclosure via graphql introspection in openshift — Red Hat OpenShift Container Platform 4.16CWE-200 5.3 Medium2024-10-22
CVE-2024-50311 Graphql: denial of service (dos) vulnerability via graphql batching — Red Hat OpenShift Container Platform 4.18CWE-770 6.5 Medium2024-10-22
CVE-2024-43168 Unbound: heap-buffer-overflow in unbound — Red Hat Enterprise Linux 6CWE-122 4.8 Medium2024-08-08
CVE-2024-43167 Unbound: null pointer dereference in unbound — Red Hat Enterprise Linux 6CWE-476 2.8 Low2024-08-08
CVE-2024-5891 Quay: unauthorized user may authenticate via oauth application token — Red Hat Quay 3CWE-1390 4.2 Medium2024-06-12
CVE-2024-3657 389-ds-base: potential denial of service via specially crafted kerberos as-req request — Red Hat Directory Server 11.5 E4S for RHEL 8CWE-20 7.5 High2024-05-28
CVE-2023-6236 Eap: oidc app attempting to access the second tenant, the user should be prompted to log — Red Hat JBoss Enterprise Application Platform 8CWE-345 7.3 High2024-04-10
CVE-2024-3446 Qemu: virtio: dma reentrancy issue leads to double free vulnerability — Red Hat Enterprise Linux 8CWE-415 8.2 High2024-04-09
CVE-2023-5685 Xnio: stackoverflowexception when the chain of notifier states becomes problematically big — Red Hat build of Apache Camel 4.4.0 for Spring BootCWE-400 7.5 High2024-03-22
CVE-2024-1394 Golang-fips/openssl: memory leaks in code encrypting and decrypting rsa payloads — Red Hat Ansible Automation Platform 2.4 for RHEL 8CWE-401 7.5 High2024-03-21
CVE-2023-7250 Iperf3: possible denial of service — Red Hat Enterprise Linux 8CWE-183 5.3 Medium2024-03-18
CVE-2024-1013 Unixodbc: out of bounds stack write due to pointer-to-integer types conversion — Red Hat Enterprise Linux 6CWE-823 7.8 High2024-03-18
CVE-2023-6725 Tripleo-ansible: bind keys are world readable — Red Hat OpenStack Platform 17.1 for RHEL 8CWE-1220 5.5 Medium2024-03-15
CVE-2023-6917 Pcp: unsafe use of directories allows pcp to root privilege escalation — Red Hat Enterprise Linux 9CWE-367 6.0 Medium2024-02-28
CVE-2023-6681 Jwcrypto: denail of service via specifically crafted jwe — Red Hat Enterprise Linux 8CWE-400 5.3 Medium2024-02-12
CVE-2024-1151 Kernel: stack overflow problem in open vswitch kernel module leading to dos — Red Hat Enterprise Linux 9CWE-121 5.5 Medium2024-02-11
CVE-2023-6536 Kernel: null pointer dereference in __nvmet_req_complete — Red Hat Enterprise Linux 8CWE-476 6.5 Medium2024-02-07

This page lists every published CVE security advisory associated with RED HAT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.