|
209081
|
5.5 |
MEDIUM
Local
|
redhat
|
keycloak
|
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confi…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-1698
|
2024-11-21 14:11 |
2020-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209082
|
4.2 |
MEDIUM
Network
|
redhat
|
soteria jboss_enterprise_application_platform openshift_application_runtimes jboss_enterprise_application_platform_continuous_delivery
|
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Ely…
|
CWE-20
Improper Input Validation
|
CVE-2020-1732
|
2024-11-21 14:11 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209083
|
9.8 |
CRITICAL
Network
|
apache
|
syncope
|
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL express…
|
CWE-74
Injection
|
CVE-2020-1961
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209084
|
9.8 |
CRITICAL
Network
|
apache
|
syncope
|
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) …
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-1959
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209085
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an un…
|
CWE-22
Path Traversal
|
CVE-2020-1631
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209086
|
7.8 |
HIGH
Local
|
huawei
|
pcmanager
|
Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can injec…
|
NVD-CWE-noinfo
|
CVE-2020-1817
|
2024-11-21 14:11 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209087
|
7.0 |
HIGH
Local
|
gnu canonical netapp debian
|
glibc ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node h410c_firmware debian_linux
|
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid user…
|
-
|
CVE-2020-1752
|
2024-11-21 14:11 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209088
|
4.9 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of…
|
NVD-CWE-Other
|
CVE-2020-1774
|
2024-11-21 14:11 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209089
|
9.8 |
CRITICAL
Network
|
redhat
|
undertow
|
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote…
|
NVD-CWE-noinfo
|
CVE-2020-1745
|
2024-11-21 14:11 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209090
|
8.6 |
HIGH
Network
|
kiali redhat
|
kiali openshift_service_mesh
|
An insufficient JWT validation vulnerability was found in Kiali versions 0.4.0 to 1.15.0 and was fixed in Kiali version 1.15.1, wherein a remote attacker could abuse this flaw by stealing a valid JWT…
|
CWE-613 CWE-384
Insufficient Session Expiration Session Fixation
|
CVE-2020-1762
|
2024-11-21 14:11 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|