|
209821
|
4.3 |
MEDIUM
Network
|
redhat
|
keycloak single_sign-on openshift_application_runtimes
|
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account ma…
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-1724
|
2024-11-21 14:11 |
2020-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209822
|
5.5 |
MEDIUM
Local
|
redhat
|
keycloak
|
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confi…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2020-1698
|
2024-11-21 14:11 |
2020-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209823
|
4.2 |
MEDIUM
Network
|
redhat
|
soteria jboss_enterprise_application_platform openshift_application_runtimes jboss_enterprise_application_platform_continuous_delivery
|
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Ely…
|
CWE-20
Improper Input Validation
|
CVE-2020-1732
|
2024-11-21 14:11 |
2020-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209824
|
9.8 |
CRITICAL
Network
|
apache
|
syncope
|
Vulnerability to Server-Side Template Injection on Mail templates for Apache Syncope 2.0.X releases prior to 2.0.15, 2.1.X releases prior to 2.1.6, enabling attackers to inject arbitrary JEXL express…
|
CWE-74
Injection
|
CVE-2020-1961
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209825
|
9.8 |
CRITICAL
Network
|
apache
|
syncope
|
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) …
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2020-1959
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209826
|
9.8 |
CRITICAL
Network
|
juniper
|
junos
|
A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Zero Touch Provisioning (ZTP) allows an un…
|
CWE-22
Path Traversal
|
CVE-2020-1631
|
2024-11-21 14:11 |
2020-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209827
|
7.8 |
HIGH
Local
|
huawei
|
pcmanager
|
Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can injec…
|
NVD-CWE-noinfo
|
CVE-2020-1817
|
2024-11-21 14:11 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209828
|
7.0 |
HIGH
Local
|
gnu canonical netapp debian
|
glibc ubuntu_linux steelstore_cloud_integrated_storage active_iq_unified_manager solidfire hci_management_node h410c_firmware debian_linux
|
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid user…
|
-
|
CVE-2020-1752
|
2024-11-21 14:11 |
2020-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209829
|
4.9 |
MEDIUM
Network
|
otrs debian
|
otrs debian_linux
|
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of…
|
NVD-CWE-Other
|
CVE-2020-1774
|
2024-11-21 14:11 |
2020-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209830
|
9.8 |
CRITICAL
Network
|
redhat
|
undertow
|
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote…
|
NVD-CWE-noinfo
|
CVE-2020-1745
|
2024-11-21 14:11 |
2020-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|