Where
-Infinity
0

Vendor Risk Score

See how red hat compares to other vendors in security performance

View Risk Score →

Software

red hat red hat enterprise linux for x86_64 - update services for sap solutions
2669
red hat red hat enterprise linux server for power le - update services for sap solutions
2634
red hat red hat enterprise linux server - aus
2277
red hat red hat enterprise linux for arm 64 - 4 years of updates
2179
red hat red hat enterprise linux for ibm z systems - 4 years of updates
2125
red hat red hat enterprise linux for x86_64
2056
red hat red hat enterprise linux for power, little endian
2032
red hat red hat enterprise linux for arm 64
2011
red hat red hat enterprise linux for power, little endian - extended update support
2001
red hat red hat enterprise linux for x86_64 - extended update support
1976
red hat red hat enterprise linux for arm 64 - extended update support
1973
red hat red hat enterprise linux for ibm z systems
1929
red hat red hat enterprise linux for ibm z systems - extended update support
1891
red hat red hat enterprise linux for x86_64 - extended life cycle
1327
red hat red hat enterprise linux for power, little endian - extended life cycle
1293
red hat red hat enterprise linux for arm 64 - extended life cycle
1249
red hat red hat enterprise linux for ibm z systems - extended life cycle
1218
red hat enterprise linux server
800
red hat enterprise linux for sap solutions
785
red hat enterprise linux for power, little endian - extended update support
784
red hat enterprise linux server for power le - update services for sap solutions
784
red hat red hat enterprise linux server - tus
749
red hat red hat codeready linux builder for x86_64 - extended update support
736
red hat red hat codeready linux builder for arm 64 - extended update support
734
red hat red hat codeready linux builder for power, little endian - extended update support
731
red hat red hat codeready linux builder for x86_64
721
red hat red hat codeready linux builder for arm 64
717
red hat enterprise linux server for ibm z systems
714
red hat red hat codeready linux builder for power, little endian
711
red hat red hat codeready linux builder for ibm z systems - extended update support
701
red hat red hat codeready linux builder for ibm z systems
635
red hat red hat enterprise linux for power, little endian - 4 years of support
586
red hat red hat enterprise linux for x86_64 - 4 years of updates
582
red hat openshift container platform
570
red hat enterprise linux for arm 64
568
red hat red hat enterprise linux for x86_64 - extended update support extension
531
red hat enterprise linux 8
489
red hat red hat openshift container platform
483
red hat enterprise linux for arm64 eus
457
red hat enterprise linux for x86_64 - extended update support
422
red hat enterprise linux for ibm z systems
414
red hat red hat openshift container platform for power
272
red hat red hat hardened images
271
red hat red hat openshift container platform for arm 64
271
red hat red hat openshift container platform for ibm z and linuxone
270
red hat red hat enterprise linux for x86_64 - extended life cycle long life
229
red hat codeready linux builder for x86_64 - extended update support
228
red hat codeready linux builder for ibm z systems
196
red hat red hat enterprise linux server for arm 64 - 4 years of updates
174
red hat openshift container platform for ibm linuxone
164
Severity
5.5
EPSS
0.11%
Buffer Overflow
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, specifically an untrusted page length field, can lead to a stack buffer overflow in the sgparsevpd80() function during serial number parsing. Successful exploitation could result in a denial of service by crashing or destabilizing the process querying the serial number.

1 / 2
Source: MITRE
First published (updated )
Severity
7

Important: OpenShift Container Platform 4.15.69 packages and security update

First published (updated )
Severity
5.3
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the full instance inventory (node hostnames, node types, UUIDs, heartbeats, capacities, and exact versions), all instance-group names and membership, the deployment install UUID, and the active control node. A remote, unauthenticated attacker can use this to map the control plane and fingerprint software versions for targeted attacks. This flaw affects confidentiality only; it does not expose secrets, credentials, or tenant data.

1 / 2
Source: MITRE
First published (updated )
Severity
4.3
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This allows a delegated administrator with basic search privileges to view detailed information about all groups assigned to a role, bypassing intended security restrictions that should limit their view to specific groups.

First published (updated )
Severity
7

Important: Red Hat Build of Apache Camel 4.18.4 for Spring Boot release.

First published (updated )
Severity
6.8
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATUREOIDCWORKLOADIDENTITYENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.

First published (updated )
Severity
6.6
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:N

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments — where the customer holds controller superuser but the platform operator runs the mesh — this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle.

1 / 2
Source: MITRE
First published (updated )
Severity
9.1
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

A flaw was found in AWX. The container group podspecoverride field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the lng and ns query parameters in the /locales/resource.json endpoint. This allows the attacker to read sensitive .json files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against registered dynamic-plugin backends.

1 / 2
Source: MITRE
First published (updated )
Severity
7

Important: python-cryptography security update

First published (updated )
Severity
7

Important: python-cryptography security update

First published (updated )
Severity
7

Important: acl security update

First published (updated )

Red Hat Hardened Images RPMs Security Update

First published (updated )
Severity
7.2
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOGAGGREGATORHOST, LOGAGGREGATORMAXDISKUSAGEPATH and LOGAGGREGATORRSYSLOGDERRORLOGFILE — into an rsyslog RainerScript config file without neutralizing RainerScript syntax. A privileged (superuser) user can inject rsyslog directives, including an omprog action, causing arbitrary command execution inside the control-plane rsyslog component. This allows disclosure of the controller SECRETKEY and database credentials, decryption of all stored credentials, and full compromise of the control plane.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the Ansible Automation Platform automation-controller workflow subsystem. WorkflowJobNode.ancestorartifacts (awx/main/models/workflow.py:262-266) is a JSONBlob column that the workflow task-manager fills with the raw merged setstats artifacts of every upstream node's job (geteffectiveartifacts) and, for child workflows, with the parent workflow's aggregated artifacts (seedrootancestorartifacts, workflow.py:743-753). The field is deliberately omitted from WorkflowJobNodeSerializer and Ansible's ansiblenolog flag is honored only after the raw dict has been persisted: in getjobkwargs (workflow.py:352-370) the aggregated artifacts are assigned and saved at lines 360-361, and only afterwards (lines 363-370) are the nolog keys copied into the child job's surveypasswords mask, leaving the ancestorartifacts column itself unredacted. Because the field is not wrapped in preventsearch(), the django-ansible-base FieldLookupBackend admits arbitrary contains/regex/startswith lookups against it. A principal with readrole on the WorkflowJob can issue GET /api/controller/v2/workflowjobnodes/?id=<n>&ancestorartifactscontains=<probe> and use the response count as a boolean oracle to recover the full JSON of the hidden column, including values protected with setstats nolog. In addition, because the credential-types list endpoint is readable by any authenticated user (CredentialTypeAccess.filteredqueryset returns all objects), and because a regular-expression lookup bypasses the JSONField cross-relation guard that rejects icontains, a user with no roles can reach the same column across all organizations via GET /api/controller/v2/credentialtypes/?credentialsworkflowjobnodesancestorartifacts regex=<probe> whenever a workflow node carries a prompted credential. This defeats both the serializer-level omission of the field and Ansible's nolog artifact-masking control, and enables cross-tenant recovery of secrets passed between workflow stages via setstats. This is a variant, on a previously unreported adjacent field, of the earlier Job/JobEvent artifact and stdout preventsearch gaps.

1 / 2
Source: Red Hat
First published (updated )
Severity
7.1
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

A flaw was found in the automation-controller input-validation guard sanitizejinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accepted while remaining valid Jinja. Because sanitizejinja() is the sole guard on several launch-time fields — ad-hoc command moduleargs, Machine-credential username / becomemethod / becomeuser, and inventory host names — a low-privileged user can inject Jinja that ansible-core evaluates in the execution environment. This enables execution of arbitrary commands in the execution environment (bypassing an administrator's ADHOCCOMMANDS module allowlist) and disclosure of secrets belonging to credentials the attacker cannot read (by templating a co-attached credential's injected environment variables), across the credential access-control boundary.

1 / 2
Source: MITRE
First published (updated )
Severity
6.8
EPSS
0.24%
AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue occurs when the system evaluates specific HTTP headers to determine if a one-time password (OTP) should be skipped, but fails to verify if those headers came from a trusted source. This could allow an attacker who already has a user's password to bypass the second-factor authentication by providing a specially crafted header in their request.

1 / 2
Source: MITRE
First published (updated )
Severity
2.7
AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

A flaw was found in automation-controller. The notification template Jinja whitelist only inspects static Getattr AST nodes. An attacker with notification template admin privileges can bypass the whitelist using dynamic subscript expressions or conditional gating on runtime values that differ from the test-render stub. Exceptions raised during notification rendering write full Python tracebacks into the notification body, which is sent to the attacker-controlled webhook URL, leaking install paths, Python version, and source file line numbers.

1 / 2
Source: Red Hat
First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

A flaw was found in automation-controller. The LaunchConfigurationBaseSerializer used by Schedule and WorkflowJobTemplateNode does not implement ▎ validatescmbranch() to reject leading-dash values, unlike the Project, JobTemplate, and JobLaunch serializers. An attacker can set scmbranch to a value such as --upload-pack=/bin/id via the schedule or workflow node API. The injection is currently blocked by a runtime ValueError check in the task layer, but the API validation gap creates a latent risk if that defense-in-depth guard is ever refactored away.

1 / 2
Source: Red Hat
First published (updated )
Severity
3.1
AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

A flaw was found in automation-controller. RunAdHocCommand.buildargs() appends the limit field as a bare positional argument instead of using the -l flag prefix as RunJob does. An attacker can set the limit field to a value beginning with a dash, which is then parsed as an ansible CLI option. The impact is currently limited to short-circuit flags such as --version and --help because the injected element displaces the required pattern positional argument.

1 / 2
Source: Red Hat
First published (updated )
Severity
8.7
XSS
AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or escaped, so a low-privileged user who can produce output -- or an external party whose data a playbook echoes -- can embed a javascript: link that is rendered into a text/html response with no Content-Security-Policy. When a higher-privileged user views the output page and clicks the link, attacker- controlled JavaScript executes in their authenticated session, allowing actions as that user up to full platform takeover.

1 / 2
Source: MITRE
First published (updated )
Severity
8.7
AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute and item traversal on its arguments, an administrator can craft a template that walks from the user object into the application settings and reads the Django secret key and the database password. The formatted message is written to a logger that can be forwarded to an external log aggregator, whose destination is also administrator-controlled, allowing the secrets to be sent off the host. An authenticated administrator can thereby obtain the master encryption key used to protect all stored credentials and the database service password, enabling offline decryption of every stored credential, forgery of user sessions, and direct access to the controller database.

1 / 2
Source: MITRE
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification configuration is protected from API filtering, its recipient value is copied in clear text into the unprotected Notification.recipients field on every send. Because the credential-types endpoint is listable by any authenticated user and the API filter backend traverses object relations without per-hop authorization, a user with no privileges can use a relational filter as a boolean count-oracle to recover, character by character and across organizations, the secret recipient values of other tenants' notifications — including PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook bearer-token URLs. This flaw affects confidentiality.

1 / 2
Source: MITRE
First published (updated )
Severity
6.6
AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

A flaw was found in the Ansible Automation Platform automation-controller system-job dispatcher. SystemJobTemplateLaunch.post (awx/api/views/init.py:3802-3805) calls createunifiedjob with the request's extravars directly and never invokes acceptorignorejobkwargs, so the "days" integer validator in SystemJobTemplate.acceptorignorevariables (awx/main/models/jobs.py: 1234-1245) is not applied on the launch path; createunifiedjob (awx/main/models/unifiedjobs.py: 369-400) copies the extravars dict onto the SystemJob verbatim after checking only key names. RunSystemJob.buildargs (awx/main/tasks/jobs.py:2113-2134) then appends str(days) to the awx-manage argument list without integer coercion, and RunSystemJob.writeargsfile (jobs.py: 2136-2137) writes ' '.join(args) to the ansible-runner args file, which ansible-runner re-tokenizes with shlex.split. A "days" value such as "5 --pythonpath /path" therefore splits into extra awx-manage arguments. RunSystemJob.buildexecutionenvironmentparams returns {} (jobs.py:2110-2111) and the dispatcher runs ansiblerunner.interface.run() in-process for SystemJob instances (jobs.py:773-781) — system jobs are the only unified-job class executed without receptor/podman isolation — so the injected arguments reach an uncontainerized control-plane awx-manage process running as the awx user with access to SECRETKEY, database credentials, and the receptor control socket. Django's handledefaultoptions parses global options such as --pythonpath from the argument vector and inserts the attacker-supplied directory at the front of sys.path. Only a superuser can trigger this (SystemJobTemplateAccess.canstart is decorated @checksuperuser, awx/main/access.py:1770-1773). Full code execution additionally requires a top-level module imported for the first time after handledefaultoptions; no such import exists in the current cleanupjobs / cleanupactivitystream import graph, so the issue is confirmed as argument injection with control of the process argument vector and sys.path[0], with code execution unproven.

Upstream: https://github.com/ansible/tower (awx) Affected file: awx/main/tasks/jobs.py:2136-2137 (RunSystemJob.writeargsfile — ' '.join(args), root cause); jobs.py:2113-2134 (buildargs, no int() coercion); jobs.py: 2110-2111 + 773-781 (uncontainerized in-process execution);

1 / 2
Source: Red Hat
First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unifiedjobtemplate, and credentials of each cloned node and fails to check the instancegroups (and executionenvironment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup userole boundary and causing attacker-influenced automation to run in the control-plane execution context.

1 / 2
Source: MITRE
First published (updated )
Severity
4.2
EPSS
0.17%
AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

A flaw was found in Keycloak's Level of Authentication (LoA) enforcement within the ConditionalLoaAuthenticator component. When a client requests a specific acr level as essential:true via the OIDC claims request parameter and an existing SSO session is present, Keycloak can silently issue a token asserting a lower acr level than required without triggering the mandatory forced-level failure. The vulnerability exists because when the browser flow re-evaluates an existing session via the Cookie authenticator, LoA-gated Conditional sub-flows may be disabled (e.g., if the user lacks the required credentials for the higher level). In this scenario, the ConditionalLoaAuthenticator fails to register its top-flow-success callback. Consequently, the onTopFlowSuccess() method is never executed, and the mandatory forced-level check is bypassed. An authenticated attacker with a valid low-level session can exploit this to obtain tokens for clients requiring higher authentication levels (essential:true) without providing the necessary additional factors. This results in an authentication level bypass for relying parties that trust the acr claim to guarantee the level was verified during the current authentication.

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: firefox security update

First published (updated )
Severity
7

Important: gstreamer1-plugins-good security update

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203