Where
AND
-Infinity
0

Vendor Risk Score

See how red hat compares to other vendors in security performance

View Risk Score →

Software

red hat red hat enterprise linux for x86_64 - update services for sap solutions
25
red hat red hat enterprise linux server for power le - update services for sap solutions
25
red hat red hat enterprise linux for x86_64 - extended life cycle
21
red hat red hat enterprise linux for power, little endian - extended life cycle
20
red hat red hat enterprise linux for power, little endian - extended update support
20
red hat red hat enterprise linux for x86_64 - extended update support
20
red hat red hat enterprise linux server - aus
20
red hat red hat enterprise linux for arm 64 - 4 years of updates
18
red hat red hat enterprise linux for ibm z systems - 4 years of updates
18
red hat openshift container platform
17
red hat red hat enterprise linux for arm 64
17
red hat red hat enterprise linux for arm 64 - extended update support
17
red hat red hat enterprise linux for ibm z systems - extended update support
17
red hat red hat enterprise linux for x86_64
17
red hat red hat openshift container platform
17
red hat red hat enterprise linux for power, little endian
16
red hat red hat enterprise linux for arm 64 - extended life cycle
15
red hat red hat enterprise linux for ibm z systems - extended life cycle
15
red hat red hat enterprise linux for ibm z systems
14
red hat red hat ansible automation platform
10
red hat red hat openshift container platform for arm 64
10
red hat red hat openshift container platform for ibm z and linuxone
10
red hat red hat openshift container platform for power
10
red hat advanced cluster management for kubernetes
8
red hat red hat openshift ai
8
red hat multicluster engine for kubernetes
7
red hat multicluster engine
6
red hat multicluster global hub
6
red hat red hat codeready linux builder for arm 64
6
red hat red hat codeready linux builder for power, little endian
6
red hat red hat codeready linux builder for x86_64
6
red hat red hat enterprise linux for power, little endian - 4 years of support
6
red hat red hat enterprise linux for x86_64 - 4 years of updates
6
red hat red hat satellite
6
red hat enterprise linux for power, little endian - extended update support
5
red hat enterprise linux server for ibm z systems
5
red hat openshift
5
red hat red hat ai inference server
5
red hat red hat build of keycloak
5
red hat red hat codeready linux builder for arm 64 - extended update support
5
red hat red hat codeready linux builder for ibm z systems
5
red hat red hat codeready linux builder for ibm z systems - extended update support
5
red hat red hat codeready linux builder for power, little endian - extended update support
5
red hat red hat codeready linux builder for x86_64 - extended update support
5
red hat red hat enterprise linux server - tus
5
red hat red hat openshift service mesh
5
red hat enterprise linux server
4
red hat enterprise linux 8
3
red hat openshift developer tools and services
3
red hat openshift gitops
3
Severity
9

Critical: Updated Container Images: HawtIO 4.4.1 for Red Hat build of Apache Camel 4 Release and security update.

First published (updated )
Severity
9

Critical: redhat-ds:11 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: redhat-ds:11 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: 389-ds:1.4 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: 389-ds-base security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: redhat-ds:12 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: redhat-ds:12 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: 389-ds-base security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: 389-ds:1.4 security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: 389-ds-base security, bug fix, and enhancement update

First published (updated )
Severity
9

Critical: Red Hat Update Infrastructure 5.3 Technology Preview security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Red Hat build of Keycloak 26.6.6 Security Update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Red Hat build of Keycloak 26.6.6 Images Security Update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Red Hat build of Keycloak 26.4.15 Security Update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Red Hat build of Keycloak 26.4.15 Images Security Update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.4.8 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.5.7 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.6.5 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.16.68 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.

1 / 2
Source: NVD
First published (updated )
Severity
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). The Application propagation controller takes the tenant-controlled ocm-managed-cluster annotation verbatim from an Application CR and uses it as the ManifestWork namespace without authorization checks. The only validation is a bare existence check on the target ManagedCluster. A tenant with Application create permissions in any hub namespace can generate ManifestWorks targeting arbitrary managed clusters, resulting in spoke cluster-admin ArgoCD syncing attacker-controlled manifests.

Upstream repo: https://github.com/stolostron/multicloud-integrations Audited commit: d88a168 Jira tracker: ACM-38643

1 / 2
Source: Red Hat
First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). The application-manager addon's ClusterRole grants apiGroups: resources: verbs: (plus nonResourceURLs:) and is bound to the application-manager ServiceAccount on every managed cluster via the addon framework. This wildcard RBAC is the root enabler for multiple confused-deputy attacks where a namespace-admin tenant can create Subscription CRs that deploy arbitrary cluster-scoped resources using this privileged SA. A least-privilege variant exists in addon/manifests/permission/role.yaml but is not used by default.

Upstream repo: https://github.com/stolostron/multicloud-operators-subscription Audited commit: 48ae4defaa5b719e0664e1de7413c96029c938bc Jira tracker: ACM-38624

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 3.3.6 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 3.4.3 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 2.25.10 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.7.2 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.8.1 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.17.56 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9.1
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

A flaw was found in the Keycloak reset-credentials authentication flow. The vulnerability exists in the way the flow state is managed, allowing an unauthenticated remote attacker to bypass the email verification requirement. By sending a specially crafted request to the reset-credentials endpoint, an attacker can transition the authentication session directly to the password update phase without possessing the required action token typically sent via email. Successful exploitation allows an attacker to perform a complete account takeover of any user, including administrative accounts, by resetting their password.

1 / 2
Source: Red Hat
First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in 389 Directory Server (389-ds-base). During SASL PLAIN authentication, the idssaslcanonuser() function writes the resolved bind DN into a Cyrus SASL auxiliary property (propset) on every canonicalization attempt, including failed ones. A failed one-shot PLAIN exchange does not trigger SASL-context recreation in idssaslcheckbind() -- that only happens when CONNFLAGSASLCOMPLETE or continuing is already set. A subsequent successful SASL bind on the same connection retrieves the auxiliary property via propgetnames() and unconditionally trusts only the first stored value (dnval[0].values[0]), with no check on which SASL mechanism completed the second exchange and no check that the value corresponds to the identity actually just authenticated.

An unprivileged remote attacker can exploit this with zero valid credentials: first send a SASL PLAIN bind as cn=Directory Manager with an incorrect password (fails as expected, but leaves the Directory Manager DN in slot 0 of the auxiliary property), then complete a SASL ANONYMOUS bind on the same connection. The server installs the stale Directory Manager identity instead of the anonymous identity, granting full Directory Manager authority. This was independently confirmed by Red Hat Product Security in an isolated, network-disconnected sandbox against 389-ds-base-2.9.0: "Who Am I?" returned "cn=directory manager", and the Directory-Manager-only cn=config attribute nsslapd-rootdn became readable. The same stale-identity mechanism also allows escalation via a valid low-privileged account's own successful second bind (originally reported variant, requiring one valid account), independently reproduced against the reporter's own PoC.

Root cause: ldap/servers/slapd/saslbind.c, idssaslcanonuser() (identity write, unconditional per mechanism) and idssaslcheckbind() (identity read-back and installation, no mechanism check, no freshness check). Verified directly against commit 33c0e0115c03017ba94ee02f144383704de32a25; unchanged since a September 2024 logging-format cleanup.

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203