|
208571
|
5.4 |
MEDIUM
Network
|
redhat dogtagpki
|
certificate_system dogtagpki
|
A flaw was found in the all pki-core 10.x.x versions, where Token Processing Service (TPS) where it did not properly sanitize Profile IDs, enabling a Stored Cross-Site Scripting (XSS) vulnerability w…
|
-
|
CVE-2020-1696
|
2024-11-21 14:11 |
2020-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208572
|
7.0 |
HIGH
Local
|
redhat
|
template_service_broker_operator
|
A vulnerability was found in openshift/template-service-broker-operator in all 4.x.x versions prior to 4.3.0, where an insecure modification vulnerability in the /etc/passwd file was found in the ope…
|
-
|
CVE-2020-1705
|
2024-11-21 14:11 |
2020-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208573
|
6.5 |
MEDIUM
Network
|
postgresql redhat
|
postgresql decision_manager enterprise_linux software_collections
|
A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to …
|
CWE-862
Missing Authorization
|
CVE-2020-1720
|
2024-11-21 14:11 |
2020-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208574
|
3.9 |
LOW
Local
|
redhat
|
cloudforms_management_engine ansible_tower ansible openstack
|
A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be se…
|
CWE-88
Argument Injection
|
CVE-2020-1738
|
2024-11-21 14:11 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208575
|
4.7 |
MEDIUM
Local
|
redhat debian fedoraproject
|
cloudforms_management_engine ansible_tower openstack ansible debian_linux fedora
|
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, …
|
-
|
CVE-2020-1740
|
2024-11-21 14:11 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208576
|
3.3 |
LOW
Local
|
redhat fedoraproject
|
cloudforms_management_engine ansible_tower ansible openstack fedora
|
A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does n…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-1736
|
2024-11-21 14:11 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208577
|
4.6 |
MEDIUM
Local
|
redhat debian fedoraproject
|
cloudforms_management_engine ansible_tower openstack ansible debian_linux fedora
|
A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All ver…
|
-
|
CVE-2020-1735
|
2024-11-21 14:11 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208578
|
5.5 |
MEDIUM
Local
|
redhat debian fedoraproject
|
ansible_tower ansible_engine debian_linux fedora
|
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubern…
|
-
|
CVE-2020-1753
|
2024-11-21 14:11 |
2020-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208579
|
10.0 |
CRITICAL
Network
|
apache oracle
|
commons_configuration database_server healthcare_foundation
|
Apache Commons Configuration uses a third-party library to parse YAML files which by default allows the instantiation of classes if the YAML includes special statements. Apache Commons Configuration …
|
NVD-CWE-noinfo
|
CVE-2020-1953
|
2024-11-21 14:11 |
2020-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208580
|
9.1 |
CRITICAL
Network
|
linuxfoundation
|
osquery
|
Incorrect validation of the TLS SNI hostname in osquery versions after 2.9.0 and before 4.2.0 could allow an attacker to MITM osquery traffic in the absence of a configured root chain of trust.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-1887
|
2024-11-21 14:11 |
2020-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|