Show filters
5,420 Total Results
Displaying 201-210 of 5,420
Sort by:
Attacker Value
Unknown
CVE-2023-2585
Disclosure Date: December 21, 2023 (last updated May 03, 2024)
Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible unauthorized access to an existing OAuth client.
0
Attacker Value
Unknown
CVE-2023-6918
Disclosure Date: December 19, 2023 (last updated May 22, 2024)
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case, non-matching keys will result in decryption/integrity failures, terminating the connection.
0
Attacker Value
Unknown
CVE-2023-6927
Disclosure Date: December 18, 2023 (last updated June 12, 2024)
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
0
Attacker Value
Unknown
CVE-2023-5384
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
0
Attacker Value
Unknown
CVE-2023-5236
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.
0
Attacker Value
Unknown
CVE-2023-5115
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
0
Attacker Value
Unknown
CVE-2023-5056
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in the Skupper operator, which may permit a certain configuration to create a service account that would allow an authenticated attacker in the adjacent cluster to view deployments in all namespaces in the cluster. This issue permits unauthorized viewing of information outside of the user's purview.
0
Attacker Value
Unknown
CVE-2023-4320
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage to the system's integrity.
0
Attacker Value
Unknown
CVE-2023-3629
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST, Cache retrieval endpoints do not properly evaluate the necessary admin permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
0
Attacker Value
Unknown
CVE-2023-3628
Disclosure Date: December 18, 2023 (last updated April 25, 2024)
A flaw was found in Infinispan's REST. Bulk read endpoints do not properly evaluate user permissions for the operation. This issue could allow an authenticated user to access information outside of their intended permissions.
0