Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat — Vulnerabilities & Security Advisories 1426

Browse all 1426 CVE security advisories affecting Red Hat. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Red Hat operates primarily as a provider of open-source enterprise software solutions, most notably its Linux operating system and container platforms. With 688 recorded Common Vulnerabilities and Exposures, the organization’s historical attack surface frequently involves remote code execution, cross-site scripting, and privilege escalation flaws within its middleware and management tools. These vulnerabilities often stem from complex codebases and third-party dependencies integrated into its distribution. Security characteristics are defined by a rigorous patching lifecycle and the Red Hat Security Response Team, which issues timely advisories for critical issues. While major public breaches directly attributed to Red Hat core infrastructure are rare, individual component flaws have occasionally allowed attackers to gain unauthorized access or execute arbitrary commands. The company maintains a strong reputation for transparency, providing detailed technical guidance to help administrators mitigate risks associated with its widely deployed enterprise technologies.

CVE ID Title CVSS Severity Published
CVE-2019-3894 Red Hat Wildfly Elytron子系统权限许可和访问控制问题漏洞 — wildfly CWE-358 8.8 - 2019-05-03
CVE-2019-3805 Red Hat Wildfly 竞争条件问题漏洞 — wildfly CWE-364 4.7 - 2019-05-03
CVE-2019-3900 Linux kernel 资源管理错误漏洞 — Kernel CWE-835 7.7 - 2019-04-25
CVE-2019-3868 Red Hat Keycloak 信息泄露漏洞 — keycloak CWE-200 3.8 - 2019-04-24
CVE-2019-3883 Red Hat 389 Directory Server 缓冲区错误漏洞 — 389-ds-base CWE-772 7.5 - 2019-04-17
CVE-2019-3891 Red Hat Satellite Candlepin组件日志信息泄露漏洞 — candlepin CWE-532 7.8 - 2019-04-12
CVE-2019-3845 Red Hat Satellite 安全漏洞 — qpid-dispatch-router CWE-284 8.8 - 2019-04-11
CVE-2017-3139 ISC BIND 输入验证错误漏洞 — BIND 7.5 - 2019-04-09
CVE-2019-3876 Red Hat OpenShift OAuth server 跨站请求伪造漏洞 — web-console CWE-352 6.1 - 2019-04-01
CVE-2019-3869 Red Hat ansible-tower 信息泄露漏洞 — Tower CWE-214 8.8 - 2019-03-28
CVE-2018-10934 Red Hat JBoss Enterprise Application Platform 跨站脚本漏洞 — wildfly-core CWE-79 5.4 - 2019-03-27
CVE-2019-3828 Ansible fetch module 路径遍历漏洞 — Ansible CWE-22 3.2 - 2019-03-27
CVE-2018-16876 Ansible 安全漏洞 — ansible CWE-200 6.5 - 2019-01-03
CVE-2018-16859 Ansible Playbooks 信息泄露漏洞 — ansible CWE-532 6.0 - 2018-11-29
CVE-2018-14655 Red Hat Keycloak 跨站脚本漏洞 — keycloak CWE-79 5.4 - 2018-11-13
CVE-2018-14657 Red Hat Keycloak 安全特征问题漏洞 — keycloak CWE-307 9.4 - 2018-11-13
CVE-2018-14658 Red Hat JBoss KeyCloak 安全漏洞 — keycloak CWE-601 6.1 - 2018-11-13
CVE-2018-14642 Red Hat Undertow 信息泄露漏洞 — undertow CWE-200 5.3 - 2018-09-18
CVE-2018-10937 Red Hat Openshift Container Platform tetonic-console组件跨站脚本漏洞 — Openshift Container Platform CWE-79 5.4 - 2018-09-11
CVE-2018-10893 Red Hat spice-client 安全漏洞 — spice-client CWE-122 9.8 - 2018-09-11
CVE-2018-10935 Red Hat 389 Directory Server 安全漏洞 — 389-ds-base CWE-400 6.5 - 2018-09-11
CVE-2018-1114 Red Hat Undertow 安全漏洞 — undertow CWE-400 7.5 - 2018-09-11
CVE-2018-1127 Red Hat Gluster Storage Tendrl API 安全漏洞 — Red Hat Gluster Storage CWE-613 8.1 - 2018-09-11
CVE-2016-7066 Red Hat JBoss Enterprise Application Platform 安全漏洞 — JBoss Enterprise Application Platform CWE-266 7.8 - 2018-09-11
CVE-2016-0750 Infinispan hotrod java客户端安全漏洞 — Infinispan CWE-138 8.8 - 2018-09-11
CVE-2016-7047 Red Hat CloudForms Management Engine 信息泄露漏洞 — cfme CWE-200 4.3 - 2018-09-11
CVE-2016-7070 Ansible Tower 权限许可和访问控制漏洞 — Ansible Tower CWE-266 8.0 - 2018-09-11
CVE-2018-14620 Red Hat Openstack 安全漏洞 — openstack-rabbitmq-container CWE-494 9.8 - 2018-09-10
CVE-2016-7041 Red Hat Drools Workbench 路径遍历漏洞 — Drools Workbench CWE-22 6.5 - 2018-09-10
CVE-2016-7061 Red hat JBoss Enterprise Application Platform 信息泄露漏洞 — EAP CWE-200 6.5 - 2018-09-10

This page lists every published CVE security advisory associated with Red Hat. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.