Red Hat / Data Grid
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-16102 | Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers | HIGH | 8.1 | Aug 5, 2026 |
| CVE-2026-15573 | Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher | HIGH | 8.1 | Aug 5, 2026 |
| CVE-2026-16093 | Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers | MEDIUM | 5.4 | Jul 17, 2026 |
| CVE-2026-15945 | Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2 | MEDIUM | 4.3 | Jul 16, 2026 |
| CVE-2026-44495 | Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge | HIGH | 7.7 | Jun 11, 2026 |
| CVE-2026-28369 | Undertow: undertow: request smuggling via malformed http request headers | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2026-28367 | Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2026-28368 | Undertow: undertow: request smuggling via inconsistent header parsing | CRITICAL | 9.1 | Mar 27, 2026 |
| CVE-2025-12543 | Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf | CRITICAL | 9.6 | Jan 7, 2026 |
| CVE-2025-5731 | Infinispan: credential leakage in infinispan cli | MEDIUM | 5.5 | Jun 26, 2025 |
| CVE-2025-23368 | Org.wildfly.core:wildfly-elytron-integration: wildfly elytron brute force attack via cli | HIGH | 8.1 | Mar 4, 2025 |
| CVE-2024-7885 | Undertow: improper state management in proxy protocol parsing causes information leakage | HIGH | 8.7 | Aug 21, 2024 |
| CVE-2023-5384 | Infinispan: credentials returned from configuration as clear text | MEDIUM | 5.1 | Dec 18, 2023 |
| CVE-2023-5236 | Infinispan: circular reference on marshalling leads to dos | HIGH | 7.1 | Dec 18, 2023 |
| CVE-2023-3629 | Infinispan: non-admins should not be able to get cache config via rest api | HIGH | 7.1 | Dec 18, 2023 |
| CVE-2023-3628 | Infispan: rest bulk ops don't check permissions | HIGH | 7.1 | Dec 18, 2023 |
| CVE-2023-4586 | Hotrod-client: hot rod client does not enable hostname validation when using tls that lead to a mitm attack | HIGH | 7.4 | Oct 4, 2023 |
| CVE-2021-31917 | Infinispan: Authentication bypass on REST endpoints when using DIGEST authentication mechanism | CRITICAL | 9.8 | Sep 21, 2021 |
| CVE-2021-3642 | wildfly-elytron: possible timing attack in ScramServer | MEDIUM | 5.3 | Aug 5, 2021 |
| CVE-2020-10771 | infinispan-server-rest: Actions with effects should not be permitted via GET requests using REST API | HIGH | 7.1 | Jun 2, 2021 |
| CVE-2021-3536 | wildfly: XSS via admin console when creating roles in domain mode | MEDIUM | 4.8 | May 20, 2021 |
| CVE-2020-25711 | infinispan: authorization check missing for server management operations | MEDIUM | 6.5 | Dec 3, 2020 |
| CVE-2020-25644 | wildfly-openssl: memory leak per HTTP session creation in WildFly OpenSSL | HIGH | 7.5 | Oct 6, 2020 |
| CVE-2019-14838 | wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default | MEDIUM | 4.9 | Oct 14, 2019 |
| CVE-2015-7501 | apache-commons-collections: InvokerTransformer code execution during deserialisation | CRITICAL | 9.8 | Nov 9, 2017 |
Showing 1 to 25 of 25 CVEs