Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.82%—Puppet Continuous Delivery18/11/202117/6/2026
A flaw was discovered in Continuous Delivery for Puppet Enterprise (CD4PE) that results in a user with lower privileges being able to access a Puppet Enterprise API token. This issue is resolved in CD4PE 4.10.0
ModificadaMedia (5.5)0.31%—Puppet Continuous Delivery18/9/202017/6/2026
Local registry credentials were included directly in the CD4PE deployment definition, which could expose these credentials to users who should not have access to them. This is resolved in Continuous Delivery for Puppet Enterprise 4.0.1.
ModificadaMedia (6.5)1.2%—Redhat AMQRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss FuseRedhat Openshift Application Runtimes+124/7/202017/6/2026
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service…
ModificadaMedia (6.5)1.2%—Redhat AMQRedhat Jboss-ejb-clientRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Jboss Fuse+224/7/202017/6/2026
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services…
ModificadaMedia (4.2)0.66%—Redhat SoteriaRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise Application Platform Continuous DeliveryRedhat Openshift Application Runtimes4/5/202017/6/2026
A flaw was found in Soteria before 1.0.1, in a way that multiple requests occurring concurrently causing security identity corruption across concurrent threads when using EE Security with WildFly Elytron which can lead to the possibility of being handled using the identity from another request.
ModificadaAlta (7.7)0.86%—Puppet Continuous Delivery26/3/202017/6/2026
In Continuous Delivery for Puppet Enterprise (CD4PE) before 3.4.0, changes to resources or classes containing Sensitive parameters can result in the Sensitive parameters ending up in the impact analysis report.
ModificadaMedia (6.5)0.88%—Puppet Continuous Delivery12/12/201917/6/2026
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console. These issues have been resolved in version 1.2.1 of the puppetlabs/cd4pe module.
ModificadaCrítica (9.8)4.5%—HP Continuous Delivery Automation12/2/201617/6/2026
HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.