Red Hat / Advanced Cluster Security
7 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-44495 | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge | HIGH | 7.7 | Jun 11, 2026 |
| CVE-2025-5198 | Stackrox: xss in stackrox | MEDIUM | 5.4 | May 27, 2025 |
| CVE-2024-0406 | Mholt/archiver: path traversal vulnerability | HIGH | 7.8 | Apr 6, 2024 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 5.9 | Dec 18, 2023 |
| CVE-2023-4958 | Stackrox: missing http security headers allows for clickjacking in web ui | MEDIUM | 6.1 | Dec 12, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2022-1902 | stackrox: Improper sanitization allows users to retrieve Notifier secrets from GraphQL API in plaintext | HIGH | 8.8 | Sep 1, 2022 |
Showing 1 to 7 of 7 CVEs