Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.42% | — | Heketi Project HeketiRedhat Gluster StorageRedhat Openshift Container PlatformRedhat Enterprise Linux | 24/11/2020 | 17/6/2026 | An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access to the Heketi server to read potentially sensitive information such as gluster-block passwords. | |
| Modificada | Crítica (9.8) | 1.4% | — | Redhat Openshift Container PlatformHeketi Project Heketi | 22/4/2019 | 17/6/2026 | It was found that default configuration of Heketi does not require any authentication potentially exposing the management interface to misuse. This isue only affects heketi as shipped with Openshift Container Platform 3.11. | |
| Modificada | Alta (7.8) | 0.43% | — | Heketi Project HeketiRedhat Enterprise Linux | 18/12/2017 | 17/6/2026 | An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file. | |
| Modificada | Alta (8.8) | 5.5% | — | Heketi Project HeketiRedhat Enterprise Linux | 18/12/2017 | 17/6/2026 | A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege escalation. |