Redhat
Redhat Fuse: vulnerabilidades y CVE
Redhat Fuse tiene 29 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 8 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE29
Últimos 12 meses6
Críticas8
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2015-1427 | Crítica (9.8) | 100% | ⚠ Explotación activa | 17 feb 2015 | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script. |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
| CVE-2016-4437 | Crítica (9.8) | 93% | ⚠ Explotación activa | 7 jun 2016 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-41731 | Alta (8.1) | 0.65% | — | 10 jun 2026 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined… |
| CVE-2026-28369 | Crítica (9.1) | 0.89% | — | 27 mar 2026 | A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior,… |
| CVE-2026-28368 | Crítica (9.1) | 0.89% | — | 27 mar 2026 | A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in… |
| CVE-2026-28367 | Crítica (9.1) | 0.89% | — | 27 mar 2026 | A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions… |
| CVE-2025-57849 | Media (6.4) | 0.21% | — | 13 mar 2026 | A container privilege escalation flaw was found in certain Fuse images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who… |
| CVE-2025-12543 | Crítica (9.6) | 1.4% | — | 7 ene 2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result,… |
| CVE-2025-9784 | Alta (7.5) | 2.3% | — | 2 sept 2025 | A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to… |
| CVE-2024-1635 | Alta (7.5) | 4.6% | — | 19 feb 2024 | A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and… |
| CVE-2023-1108 | Alta (7.5) | 1.8% | — | 14 sept 2023 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
| CVE-2021-4178 | Media (6.7) | 0.33% | — | 24 ago 2022 | A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to… |
| CVE-2021-3690 | Alta (7.5) | 1.7% | — | 23 ago 2022 | A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is… |
| CVE-2021-3597 | Media (5.9) | 1.1% | — | 24 may 2022 | A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting in a denial of service. The highest threat from this vulnerability is availability. This flaw… |
| CVE-2020-10688 | Media (6.1) | 1.4% | — | 27 may 2021 | A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could… |
| CVE-2020-25689 | Media (6.5) | 1.5% | — | 2 nov 2020 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to… |
| CVE-2019-14900 | Media (6.5) | 2.1% | — | 6 jul 2020 | A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or… |
| CVE-2020-10719 | Media (6.5) | 0.98% | — | 26 may 2020 | A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. |
| CVE-2019-10174 | Alta (8.8) | 3.1% | — | 25 nov 2019 | A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The… |
| CVE-2019-14860 | Media (6.5) | 1.2% | — | 8 nov 2019 | It was found that the Syndesis configuration for Cross-Origin Resource Sharing was set to allow all origins. An attacker could use this lack of protection to conduct phishing attacks and further access unauthorized… |
| CVE-2019-10219 | Media (6.1) | 2.2% | — | 8 nov 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can… |
| CVE-2019-0201 | Media (5.9) | 9.7% | — | 23 may 2019 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information… |
| CVE-2019-0204 | Alta (7.8) | 2.7% | — | 25 mar 2019 | A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to… |
| CVE-2018-1258 | Alta (8.8) | 2.5% | — | 11 may 2018 | Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to… |
| CVE-2018-1270 | Crítica (9.8) | 77% | — | 6 abr 2018 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through… |
| CVE-2018-1199 | Media (5.3) | 2.9% | — | 16 mar 2018 | Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
| CVE-2017-7957 | Alta (7.5) | 4.9% | — | 29 abr 2017 | XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated… |
| CVE-2017-5645 | Crítica (9.8) | 90% | — | 17 abr 2017 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized,… |
| CVE-2016-4437 | Crítica (9.8) | 93% | ⚠ Explotación activa | 7 jun 2016 | Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request… |
| CVE-2015-1427 | Crítica (9.8) | 100% | ⚠ Explotación activa | 17 feb 2015 | The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230