Search

Find a vulnerability

Search criteria

    23 vulnerabilities by Redhat

    CVE-2024-51127 (GCVE-0-2024-51127)

    Vulnerability from cvelistv5 – Published: 2024-11-04 00:00 – Updated: 2026-07-05 00:50
    VLAI
    Summary
    An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-06 16:04 UTC
    CWE
    • n/a
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    Impacted products
    Vendor Product Version
    redhat hornetq Affected: 0 , ≤ 2.4.9 (custom)
        cpe:2.3:a:redhat:hornetq:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:redhat:hornetq:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "hornetq",
                "vendor": "redhat",
                "versions": [
                  {
                    "lessThanOrEqual": "2.4.9",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 9.1,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-51127",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-06T16:04:11.127415Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-22",
                    "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T16:11:29.503Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "An issue in the createTempFile method of hornetq v2.4.9 allows attackers to arbitrarily overwrite files or access sensitive information."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-05T00:50:34.568Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "url": "https://github.com/JAckLosingHeart/CWE-378/blob/main/CVE-2024-51127.md"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2024-51127",
        "datePublished": "2024-11-04T00:00:00.000Z",
        "dateReserved": "2024-10-28T00:00:00.000Z",
        "dateUpdated": "2026-07-05T00:50:34.568Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-2467 (GCVE-0-2024-2467)

    Vulnerability from cvelistv5 – Published: 2024-04-25 16:45 – Updated: 2026-02-25 19:31
    VLAI
    Title
    Perl-crypt-openssl-rsa: side-channel attack in pkcs#1 v1.5 padding mode (marvin attack)
    Summary
    A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-13 20:18 UTC
    CWE
    • CWE-208 - Observable Timing Discrepancy
    Impacted products
    Vendor Product Version
    Red Hat Red Hat Enterprise Linux 6     cpe:/o:redhat:enterprise_linux:6
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 7     cpe:/o:redhat:enterprise_linux:7
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 8     cpe:/o:redhat:enterprise_linux:8
    Create a notification for this product.
    Red Hat Red Hat Enterprise Linux 9     cpe:/o:redhat:enterprise_linux:9
    Create a notification for this product.
    redhat openssl Affected: pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-6.0
    Affected: pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-7.0
    Affected: pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-8.0
    Affected: pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-9.0
        cpe:2.3:a:redhat:openssl:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-03-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:redhat:openssl:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "openssl",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-6.0"
                  },
                  {
                    "status": "affected",
                    "version": "pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-7.0"
                  },
                  {
                    "status": "affected",
                    "version": "pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-8.0"
                  },
                  {
                    "status": "affected",
                    "version": "pkg:rpm/redhat/perl-crypt-openssl-rsa@distro=redhat-enterprise-linux-9.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-2467",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-13T20:18:07.779248Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-18T15:58:16.449Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:11:53.605Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/CVE-2024-2467"
              },
              {
                "name": "RHBZ#2269567",
                "tags": [
                  "issue-tracking",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2269567"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/toddr/Crypt-OpenSSL-RSA/issues/42"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://people.redhat.com/~hkario/marvin/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "collectionURL": "https://github.com/toddr/Crypt-OpenSSL-RSA",
              "defaultStatus": "affected",
              "packageName": "perl-Crypt-OpenSSL-RSA"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:6"
              ],
              "defaultStatus": "unknown",
              "packageName": "perl-Crypt-OpenSSL-RSA",
              "product": "Red Hat Enterprise Linux 6",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:7"
              ],
              "defaultStatus": "unknown",
              "packageName": "perl-Crypt-OpenSSL-RSA",
              "product": "Red Hat Enterprise Linux 7",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:8"
              ],
              "defaultStatus": "affected",
              "packageName": "perl-Crypt-OpenSSL-RSA",
              "product": "Red Hat Enterprise Linux 8",
              "vendor": "Red Hat"
            },
            {
              "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
              "cpes": [
                "cpe:/o:redhat:enterprise_linux:9"
              ],
              "defaultStatus": "affected",
              "packageName": "perl-Crypt-OpenSSL-RSA",
              "product": "Red Hat Enterprise Linux 9",
              "vendor": "Red Hat"
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "This issue was discovered by Hubert Kario (Red Hat)."
            }
          ],
          "datePublic": "2024-03-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "A timing-based side-channel flaw exists in the perl-Crypt-OpenSSL-RSA package, which could be sufficient to recover plaintext across a network in a Bleichenbacher-style attack. To achieve successful decryption, an attacker would have to be able to send a large number of trial messages. The vulnerability affects the legacy PKCS#1v1.5 RSA encryption padding mode."
            }
          ],
          "metrics": [
            {
              "other": {
                "content": {
                  "namespace": "https://access.redhat.com/security/updates/classification/",
                  "value": "Moderate"
                },
                "type": "Red Hat severity rating"
              }
            },
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-208",
                  "description": "Observable Timing Discrepancy",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-02-25T19:31:17.530Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "vdb-entry",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/security/cve/CVE-2024-2467"
            },
            {
              "name": "RHBZ#2269567",
              "tags": [
                "issue-tracking",
                "x_refsource_REDHAT"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2269567"
            },
            {
              "url": "https://github.com/toddr/Crypt-OpenSSL-RSA/issues/42"
            },
            {
              "url": "https://people.redhat.com/~hkario/marvin/"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2024-03-14T00:00:00.000Z",
              "value": "Reported to Red Hat."
            },
            {
              "lang": "en",
              "time": "2024-03-12T00:00:00.000Z",
              "value": "Made public."
            }
          ],
          "title": "Perl-crypt-openssl-rsa: side-channel attack in pkcs#1 v1.5 padding mode (marvin attack)",
          "workarounds": [
            {
              "lang": "en",
              "value": "This CVE is mitigated (i.e. not exploitable) by using the openssl package with support for implicit rejection shipped in the following RHEL errata:\n\n* https://access.redhat.com/errata/RHSA-2024:0208\n* https://access.redhat.com/errata/RHSA-2024:0154\n* https://access.redhat.com/errata/RHSA-2023:7877\n* https://access.redhat.com/errata/RHSA-2024:0500\n* https://access.redhat.com/errata/RHBA-2023:6627"
            }
          ],
          "x_generator": {
            "engine": "cvelib 1.8.0"
          },
          "x_redhatCweChain": "CWE-208: Observable Timing Discrepancy"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2024-2467",
        "datePublished": "2024-04-25T16:45:02.948Z",
        "dateReserved": "2024-03-14T17:31:30.419Z",
        "dateUpdated": "2026-02-25T19:31:17.530Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2022-28737 (GCVE-0-2022-28737)

    Vulnerability from cvelistv5 – Published: 2023-07-20 00:26 – Updated: 2024-10-22 13:17
    VLAI
    Title
    There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables
    Summary
    There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-10-22 13:15 UTC
    Impacted products
    Vendor Product Version
    Red Hat Bootloader Team shim Affected: 0 , < 15.6 (semver)
    Create a notification for this product.
    redhat shim Affected: 0 , < 15.6 (semver)
        cpe:2.3:a:redhat:shim:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2022-06-13 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T06:03:52.700Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://www.openwall.com/lists/oss-security/2022/06/07/5"
              },
              {
                "tags": [
                  "issue-tracking",
                  "x_transferred"
                ],
                "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28737"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:redhat:shim:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "shim",
                "vendor": "redhat",
                "versions": [
                  {
                    "lessThan": "15.6",
                    "status": "affected",
                    "version": "0",
                    "versionType": "semver"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2022-28737",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-10-22T13:15:51.434701Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-22T13:17:50.789Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "packageName": "shim",
              "platforms": [
                "Linux"
              ],
              "product": "shim",
              "repo": "https://github.com/rhboot/shim/",
              "vendor": "Red Hat Bootloader Team",
              "versions": [
                {
                  "lessThan": "15.6",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Chris Coulson"
            }
          ],
          "datePublic": "2022-06-13T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "There\u0027s a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not discarded in such scenario."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-07-20T15:38:14.142Z",
            "orgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
            "shortName": "canonical"
          },
          "references": [
            {
              "tags": [
                "mailing-list"
              ],
              "url": "https://www.openwall.com/lists/oss-security/2022/06/07/5"
            },
            {
              "tags": [
                "issue-tracking"
              ],
              "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28737"
            }
          ],
          "title": "There\u0027s a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "cc1ad9ee-3454-478d-9317-d3e869d708bc",
        "assignerShortName": "canonical",
        "cveId": "CVE-2022-28737",
        "datePublished": "2023-07-20T00:26:15.627Z",
        "dateReserved": "2022-04-05T21:59:08.761Z",
        "dateUpdated": "2024-10-22T13:17:50.789Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2020-14318 (GCVE-0-2020-14318)

    Vulnerability from cvelistv5 – Published: 2020-12-03 00:00 – Updated: 2024-10-29 13:52
    VLAI
    Summary
    A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-23 14:56 UTC
    CWE
    Impacted products
    Vendor Product Version
    n/a samba Affected: samba 4.11.15, samba 4.12.9, samba 4.13.1
    redhat storage Affected: 3.0
        cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*
    Create a notification for this product.
    redhat enterprise_linux Affected: -
        cpe:2.3:o:redhat:enterprise_linux:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "storage",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "-"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 4.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "NONE",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2020-14318",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-23T14:56:23.506771Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-10-29T13:52:19.151Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T12:39:36.239Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1892631"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.samba.org/samba/security/CVE-2020-14318.html"
              },
              {
                "name": "GLSA-202012-24",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://security.gentoo.org/glsa/202012-24"
              },
              {
                "name": "[debian-lts-announce] 20240422 [SECURITY] [DLA 3792-1] samba security update",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "samba",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "samba 4.11.15, samba 4.12.9, samba 4.13.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in the way samba handled file and directory permissions. An authenticated user could use this flaw to gain access to certain file and directory information which otherwise would be unavailable to the attacker."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-04-22T16:05:59.418Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1892631"
            },
            {
              "url": "https://www.samba.org/samba/security/CVE-2020-14318.html"
            },
            {
              "name": "GLSA-202012-24",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://security.gentoo.org/glsa/202012-24"
            },
            {
              "name": "[debian-lts-announce] 20240422 [SECURITY] [DLA 3792-1] samba security update",
              "tags": [
                "mailing-list"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00015.html"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2020-14318",
        "datePublished": "2020-12-03T00:00:00.000Z",
        "dateReserved": "2020-06-17T00:00:00.000Z",
        "dateUpdated": "2024-10-29T13:52:19.151Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2015-5201 (GCVE-0-2015-5201)

    Vulnerability from cvelistv5 – Published: 2020-02-25 20:16 – Updated: 2024-08-06 06:41
    VLAI
    Summary
    VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors.
    Severity
    No CVSS data available.
    CWE
    • Weak Authentication
    Impacted products
    Vendor Product Version
    RedHat Enterprise Virtualization Hypervisor (aka RHEV-H) Affected: 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0
    Create a notification for this product.
    Date Public
    2015-08-14 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T06:41:08.567Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1253882"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://rhn.redhat.com/errata/RHEA-2015-2527.html"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1273144"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/cve-2015-5201"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Enterprise Virtualization Hypervisor (aka RHEV-H)",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0"
                }
              ]
            }
          ],
          "datePublic": "2015-08-14T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "VDSM and libvirt in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H) 7-7.x before 7-7.2-20151119.0 and 6-6.x before 6-6.7-20151117.0 as packaged in Red Hat Enterprise Virtualization before 3.5.6 when VSDM is run with -spice disable-ticketing and a VM is suspended and then restored, allows remote attackers to log in without authentication via unspecified vectors."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "Weak Authentication",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-02-25T20:16:02.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1253882"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://rhn.redhat.com/errata/RHEA-2015-2527.html"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1273144"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://access.redhat.com/security/cve/cve-2015-5201"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2015-5201",
        "datePublished": "2020-02-25T20:16:02.000Z",
        "dateReserved": "2015-07-01T00:00:00.000Z",
        "dateUpdated": "2024-08-06T06:41:08.567Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-19341 (GCVE-0-2019-19341)

    Vulnerability from cvelistv5 – Published: 2019-12-19 20:24 – Updated: 2024-08-05 02:16
    VLAI
    Summary
    A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this vulnerability.
    CWE
    References
    Impacted products
    Vendor Product Version
    RedHat Tower Affected: all ansible_tower versions 3.6.x before 3.6.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T02:16:46.897Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19341"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Tower",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "all ansible_tower versions 3.6.x before 3.6.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in \u0027/var/backup/tower\u0027 are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this vulnerability."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-12-04T18:00:59.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19341"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2019-19341",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Tower",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all ansible_tower versions 3.6.x before 3.6.2"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in \u0027/var/backup/tower\u0027 are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this vulnerability."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "5.9/CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-732"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19341",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-19341"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-19341",
        "datePublished": "2019-12-19T20:24:18.000Z",
        "dateReserved": "2019-11-27T00:00:00.000Z",
        "dateUpdated": "2024-08-05T02:16:46.897Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10172 (GCVE-0-2019-10172)

    Vulnerability from cvelistv5 – Published: 2019-11-18 16:16 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes.
    CWE
    References
    URL Tags
    https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2… x_refsource_CONFIRM
    https://lists.debian.org/debian-lts-announce/2020… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r25e25973e95… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/ra37700b8427… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r0066c1e8626… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r37eb6579fa0… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rb47911c179c… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/re07c51a8026… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/re646dcc2739… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r4bbfa1439d7… mailing-listx_refsource_MLIST
    https://lists.debian.org/debian-lts-announce/2020… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r33d25a342af… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rd3a34d663e2… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r48a32f2dd69… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rb8c09b14fd5… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r38696678003… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r80e8882c86c… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r68acf97f452… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r43c6f75d203… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r1edabcfacda… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r6dea2a887f5… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rce00a1c60f7… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r500867b74f4… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r5f16a1bd31a… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r0fbf2c60967… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r04ecadefb27… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r356592d9874… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r1f07e61b3eb… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r08e1b73fabd… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r4176155240c… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r0d8c3e32a0a… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rb036bf32e4d… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r1cc8bce2cf3… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r385c35a7c6f… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/rd27730cfc30… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r21ac3570ce8… mailing-listx_refsource_MLIST
    https://lists.apache.org/thread.html/r634468eb321… mailing-listx_refsource_MLIST
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:09.989Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172"
              },
              {
                "name": "[debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html"
              },
              {
                "name": "[cassandra-commits] 20200407 [jira] [Created] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r25e25973e9577c62fd0221b4b52990851adf11cbe33036bd67d4b13d%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200413 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/ra37700b842790883b9082e6b281fb7596f571b13078a4856cd38f2c2%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200420 [jira] [Updated] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r0066c1e862613de402fee04e81cbe00bcd64b64a2711beb9a13c3b25%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200420 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r37eb6579fa0bf94a72b6c978e2fee96f68a2b1b3ac1b1ce60aee86cf%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200420 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rb47911c179c9f3e8ea3f134b5645e63cd20c6fc63bd0b43ab5864bd1%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200818 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/re07c51a8026c11e6e5513bfdc66d52d1c1027053e480fb8073356257%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200818 [jira] [Created] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/re646dcc2739d92117bf9a76a33c600ed3b65e8b4e9b6f441e366b72b%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200819 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r4bbfa1439d7a4e1712e260bfc3d90f7cf997abfd641cccde6432d4ab%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html"
              },
              {
                "name": "[hadoop-common-issues] 20200824 [jira] [Created] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r33d25a342af84102903cd9dec8338a5bcba3ecfce10505bdfe793b92%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-dev] 20200824 [jira] [Created] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rd3a34d663e2a25b9ab1e8a1a94712cd5f100f098578aec79af48161e%40%3Ccommon-dev.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20200825 [jira] [Updated] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r48a32f2dd6976d33f7a12b7e09ec7ea1895f8facba82b565587c28ac%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20200825 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rb8c09b14fd57d855dc21e0a037dc29258c2cbe9c1966bfff453a02e4%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200901 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r386966780034aadee69ffd82d44555117c9339545b9ce990fe490a3e%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20200901 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r80e8882c86c9c17a57396a5ef7c4f08878d629a0291243411be0de3a%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r68acf97f4526ba59a33cc6e592261ea4f85d890f99e79c82d57dd589%40%3Cissues.spark.apache.org%3E"
              },
              {
                "name": "[hadoop-user] 20210317 jackson-mapper-asl vulnerability at Hadoop",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r43c6f75d203b8afc4fbd6c3200db0384a18a11c59d085b1a9bb0ccfe%40%3Cuser.hadoop.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Updated] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Assigned] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-dev] 20210318 [jira] [Created] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9%40%3Cdev.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Commented] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-dev] 20210318 CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581%40%3Cdev.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Comment Edited] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210320 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r04ecadefb27cda84b699130b11b96427f1d8a7a4066d8292f7f15ed8%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210729 [jira] [Resolved] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210906 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r1f07e61b3ebabd3e5b4aa97bf1b26d98b793fdfa29a23dac60633f55%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210907 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r08e1b73fabd986dcd2ddd7d09480504d1472264bed2f19b1d2002a9c%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210920 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r4176155240cdc36aad7869932d9c29551742c7fa630f209fb4a8e649%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210921 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r0d8c3e32a0a2d8a0b6118f5b3487d363afdda80c996d7b930097383d%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210924 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rb036bf32e4dacc49335e3bdc1be8e53d6f54df692ac8e2251a6884bd%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210924 [jira] [Updated] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r1cc8bce2cf3dfce08a64c4fa20bf38d33b56ad995cee2e382f522f83%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20210926 [jira] [Commented] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r385c35a7c6f4acaacf37fe22922bb8e2aed9d322d0fa6dc1d45acddb%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[hadoop-common-issues] 20210927 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rd27730cfc3066dfcf15927c8e800603728d5dedf17eee1f8c6e3507c%40%3Ccommon-issues.hadoop.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20210927 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r21ac3570ce865b8f1e5d26e492aeb714a6aaa53a0c9a6f72ef181556%40%3Ccommits.cassandra.apache.org%3E"
              },
              {
                "name": "[cassandra-commits] 20210927 [jira] [Assigned] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r634468eb3218ab02713128ff6f4818c618622b2b3de4d958138dde49%40%3Ccommits.cassandra.apache.org%3E"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "jackson-mapper-asl",
              "vendor": "Redhat",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.9.x"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects codehaus jackson-mapper-asl libraries but in different classes."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-611",
                  "description": "CWE-611",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-09-27T09:06:11.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10172"
            },
            {
              "name": "[debian-lts-announce] 20200131 [SECURITY] [DLA 2091-1] libjackson-json-java security update",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html"
            },
            {
              "name": "[cassandra-commits] 20200407 [jira] [Created] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r25e25973e9577c62fd0221b4b52990851adf11cbe33036bd67d4b13d%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200413 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/ra37700b842790883b9082e6b281fb7596f571b13078a4856cd38f2c2%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200420 [jira] [Updated] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r0066c1e862613de402fee04e81cbe00bcd64b64a2711beb9a13c3b25%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200420 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r37eb6579fa0bf94a72b6c978e2fee96f68a2b1b3ac1b1ce60aee86cf%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200420 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rb47911c179c9f3e8ea3f134b5645e63cd20c6fc63bd0b43ab5864bd1%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200818 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/re07c51a8026c11e6e5513bfdc66d52d1c1027053e480fb8073356257%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200818 [jira] [Created] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/re646dcc2739d92117bf9a76a33c600ed3b65e8b4e9b6f441e366b72b%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200819 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r4bbfa1439d7a4e1712e260bfc3d90f7cf997abfd641cccde6432d4ab%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[debian-lts-announce] 20200824 [SECURITY] [DLA 2342-1] libjackson-json-java security update",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html"
            },
            {
              "name": "[hadoop-common-issues] 20200824 [jira] [Created] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r33d25a342af84102903cd9dec8338a5bcba3ecfce10505bdfe793b92%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-dev] 20200824 [jira] [Created] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rd3a34d663e2a25b9ab1e8a1a94712cd5f100f098578aec79af48161e%40%3Ccommon-dev.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20200825 [jira] [Updated] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r48a32f2dd6976d33f7a12b7e09ec7ea1895f8facba82b565587c28ac%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20200825 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rb8c09b14fd57d855dc21e0a037dc29258c2cbe9c1966bfff453a02e4%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200901 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r386966780034aadee69ffd82d44555117c9339545b9ce990fe490a3e%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20200901 [jira] [Commented] (CASSANDRA-15701) Does Cassandra 3.11.3/3.11.5 is affected by CVE-2019-10712 or not ?",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r80e8882c86c9c17a57396a5ef7c4f08878d629a0291243411be0de3a%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[spark-issues] 20210223 [jira] [Created] (SPARK-34511) Current Security vulnerabilities in spark libraries",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r68acf97f4526ba59a33cc6e592261ea4f85d890f99e79c82d57dd589%40%3Cissues.spark.apache.org%3E"
            },
            {
              "name": "[hadoop-user] 20210317 jackson-mapper-asl vulnerability at Hadoop",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r43c6f75d203b8afc4fbd6c3200db0384a18a11c59d085b1a9bb0ccfe%40%3Cuser.hadoop.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Updated] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Assigned] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-dev] 20210318 [jira] [Created] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9%40%3Cdev.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Commented] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-dev] 20210318 CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581%40%3Cdev.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Comment Edited] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210320 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r04ecadefb27cda84b699130b11b96427f1d8a7a4066d8292f7f15ed8%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210729 [jira] [Resolved] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210906 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r1f07e61b3ebabd3e5b4aa97bf1b26d98b793fdfa29a23dac60633f55%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210907 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r08e1b73fabd986dcd2ddd7d09480504d1472264bed2f19b1d2002a9c%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210920 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r4176155240cdc36aad7869932d9c29551742c7fa630f209fb4a8e649%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210921 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r0d8c3e32a0a2d8a0b6118f5b3487d363afdda80c996d7b930097383d%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210924 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rb036bf32e4dacc49335e3bdc1be8e53d6f54df692ac8e2251a6884bd%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210924 [jira] [Updated] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r1cc8bce2cf3dfce08a64c4fa20bf38d33b56ad995cee2e382f522f83%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20210926 [jira] [Commented] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r385c35a7c6f4acaacf37fe22922bb8e2aed9d322d0fa6dc1d45acddb%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[hadoop-common-issues] 20210927 [jira] [Commented] (HADOOP-17225) Update jackson-mapper-asl-1.9.13 to atlassian version to mitigate: CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rd27730cfc3066dfcf15927c8e800603728d5dedf17eee1f8c6e3507c%40%3Ccommon-issues.hadoop.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20210927 [jira] [Updated] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r21ac3570ce865b8f1e5d26e492aeb714a6aaa53a0c9a6f72ef181556%40%3Ccommits.cassandra.apache.org%3E"
            },
            {
              "name": "[cassandra-commits] 20210927 [jira] [Assigned] (CASSANDRA-16056) Remove jackson-mapper-asl-1.9.13 to mitigate CVE-2019-10172",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r634468eb3218ab02713128ff6f4818c618622b2b3de4d958138dde49%40%3Ccommits.cassandra.apache.org%3E"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10172",
        "datePublished": "2019-11-18T16:16:02.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:09.989Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2013-4280 (GCVE-0-2013-4280)

    Vulnerability from cvelistv5 – Published: 2019-11-04 18:50 – Updated: 2024-08-06 16:38
    VLAI
    Summary
    Insecure temporary file vulnerability in RedHat vsdm 4.9.6.
    Severity
    No CVSS data available.
    CWE
    • /tmp file vulnerability issues
    Impacted products
    Vendor Product Version
    RedHat vdsm Affected: through 2013-07-24
    Create a notification for this product.
    Date Public
    2013-07-24 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T16:38:01.855Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://security-tracker.debian.org/tracker/CVE-2013-4280"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4280"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/cve-2013-4280"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "vdsm",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "through 2013-07-24"
                }
              ]
            }
          ],
          "datePublic": "2013-07-24T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Insecure temporary file vulnerability in RedHat vsdm 4.9.6."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "/tmp file vulnerability issues",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-11-04T18:50:52.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://security-tracker.debian.org/tracker/CVE-2013-4280"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-4280"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://access.redhat.com/security/cve/cve-2013-4280"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2013-4280",
        "datePublished": "2019-11-04T18:50:52.000Z",
        "dateReserved": "2013-06-12T00:00:00.000Z",
        "dateUpdated": "2024-08-06T16:38:01.855Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2018-5742 (GCVE-0-2018-5742)

    Vulnerability from cvelistv5 – Published: 2019-10-30 13:43 – Updated: 2024-09-17 03:53
    VLAI
    Title
    An oversight while backporting a feature leads to an assertion failure in buffer.c:420
    Summary
    While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -> bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected.
    CWE
    • An oversight by RedHat while backporting a feature leads to an assertion failure in buffer.c:420
    Assigner
    References
    Impacted products
    Vendor Product Version
    RedHat BIND9 Affected: RedHat BIND9 bind-9.9.4-65.el7 -> bind-9.9.4-72.el7
    Create a notification for this product.
    Date Public
    2018-12-18 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T05:40:51.247Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/security/cve/cve-2018-5742"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "BIND9",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "RedHat BIND9 bind-9.9.4-65.el7 -\u003e bind-9.9.4-72.el7"
                }
              ]
            }
          ],
          "datePublic": "2018-12-18T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -\u003e bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "An oversight by RedHat while backporting a feature leads to an assertion failure in buffer.c:420",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-10-30T13:43:12.000Z",
            "orgId": "404fd4d2-a609-4245-b543-2c944a302a22",
            "shortName": "isc"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://access.redhat.com/security/cve/cve-2018-5742"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "An oversight while backporting a feature leads to an assertion failure in buffer.c:420",
          "x_generator": {
            "engine": "Vulnogram 0.0.8"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "security-officer@isc.org",
              "DATE_PUBLIC": "2018-12-18T13:00:00.000Z",
              "ID": "CVE-2018-5742",
              "STATE": "PUBLIC",
              "TITLE": "An oversight while backporting a feature leads to an assertion failure in buffer.c:420"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "BIND9",
                          "version": {
                            "version_data": [
                              {
                                "version_name": "RedHat BIND9",
                                "version_value": "bind-9.9.4-65.el7 -\u003e bind-9.9.4-72.el7"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "While backporting a feature for a newer branch of BIND9, RedHat introduced a path leading to an assertion failure in buffer.c:420. Affects RedHat versions bind-9.9.4-65.el7 -\u003e bind-9.9.4-72.el7. No ISC releases are affected. Other packages from other distributions who made the same error may also be affected."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.8"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "An oversight by RedHat while backporting a feature leads to an assertion failure in buffer.c:420"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://access.redhat.com/security/cve/cve-2018-5742",
                  "refsource": "CONFIRM",
                  "url": "https://access.redhat.com/security/cve/cve-2018-5742"
                }
              ]
            },
            "source": {
              "discovery": "UNKNOWN"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "404fd4d2-a609-4245-b543-2c944a302a22",
        "assignerShortName": "isc",
        "cveId": "CVE-2018-5742",
        "datePublished": "2019-10-30T13:43:12.526Z",
        "dateReserved": "2018-01-17T00:00:00.000Z",
        "dateUpdated": "2024-09-17T03:53:09.481Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-3834 (GCVE-0-2019-3834)

    Vulnerability from cvelistv5 – Published: 2019-10-03 13:31 – Updated: 2024-08-04 19:19
    VLAI
    Summary
    It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3.
    CWE
    References
    Impacted products
    Vendor Product Version
    RedHat struts Affected: all versions under 1.3.10_1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T19:19:18.590Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3834"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "struts",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions under 1.3.10_1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.6,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-470",
                  "description": "CWE-470",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-10-03T13:31:06.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3834"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2019-3834",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "struts",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all versions under 1.3.10_1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "5.6/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-470"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3834",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3834"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-3834",
        "datePublished": "2019-10-03T13:31:06.000Z",
        "dateReserved": "2019-01-03T00:00:00.000Z",
        "dateUpdated": "2024-08-04T19:19:18.590Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10212 (GCVE-0-2019-10212)

    Vulnerability from cvelistv5 – Published: 2019-10-02 18:22 – Updated: 2024-08-04 22:17
    VLAI
    Summary
    A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
    CWE
    References
    Impacted products
    Vendor Product Version
    RedHat undertow Affected: all under 2.0.20
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:17:18.906Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212"
              },
              {
                "name": "RHSA-2019:2998",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:2998"
              },
              {
                "name": "RHSA-2020:0727",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2020:0727"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://security.netapp.com/advisory/ntap-20220210-0017/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "undertow",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "all under 2.0.20"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user\u0027s credentials from the log files."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-532",
                  "description": "CWE-532",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-02-10T09:06:38.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212"
            },
            {
              "name": "RHSA-2019:2998",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:2998"
            },
            {
              "name": "RHSA-2020:0727",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2020:0727"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://security.netapp.com/advisory/ntap-20220210-0017/"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2019-10212",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "undertow",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all under 2.0.20"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user\u0027s credentials from the log files."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "4.8/CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-532"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212"
                },
                {
                  "name": "RHSA-2019:2998",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:2998"
                },
                {
                  "name": "RHSA-2020:0727",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2020:0727"
                },
                {
                  "name": "https://security.netapp.com/advisory/ntap-20220210-0017/",
                  "refsource": "CONFIRM",
                  "url": "https://security.netapp.com/advisory/ntap-20220210-0017/"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10212",
        "datePublished": "2019-10-02T18:22:08.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:17:18.906Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10202 (GCVE-0-2019-10202)

    Vulnerability from cvelistv5 – Published: 2019-10-01 14:22 – Updated: 2024-08-04 22:17
    VLAI
    Summary
    A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike.
    CWE
    Impacted products
    Vendor Product Version
    RedHat codehaus Affected: Codehaus 1.9.x
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:17:19.913Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10202"
              },
              {
                "name": "[flume-issues] 20200221 [jira] [Created] (FLUME-3356) Probable security issue in Flume",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/refea6018a2c4e9eb7838cab567ed219c3f726dcd83a5472fbb80d8d9%40%3Cissues.flume.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Updated] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Assigned] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-dev] 20210318 [jira] [Created] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9%40%3Cdev.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Commented] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-dev] 20210318 CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581%40%3Cdev.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210318 [jira] [Comment Edited] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e%40%3Cissues.hive.apache.org%3E"
              },
              {
                "name": "[hive-issues] 20210729 [jira] [Resolved] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a%40%3Cissues.hive.apache.org%3E"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "codehaus",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "Codehaus 1.9.x"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A series of deserialization vulnerabilities have been discovered in Codehaus 1.9.x implemented in EAP 7. This CVE fixes CVE-2017-17485, CVE-2017-7525, CVE-2017-15095, CVE-2018-5968, CVE-2018-7489, CVE-2018-1000873, CVE-2019-12086 reported for FasterXML jackson-databind by implementing a whitelist approach that will mitigate these vulnerabilities and future ones alike."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-502",
                  "description": "CWE-502",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-07-29T09:06:09.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10202"
            },
            {
              "name": "[flume-issues] 20200221 [jira] [Created] (FLUME-3356) Probable security issue in Flume",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/refea6018a2c4e9eb7838cab567ed219c3f726dcd83a5472fbb80d8d9%40%3Cissues.flume.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Updated] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r1edabcfacdad42d3c830464e9cf07a9a489059a7b7a8642cf055542d%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Assigned] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r6dea2a887f5eb1d68f124d64b14cd1a04f682f06de8cd01b7e4214e0%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-dev] 20210318 [jira] [Created] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rce00a1c60f7df4b10e72fa87827c102f55b074bb91993631df2c21f9%40%3Cdev.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Commented] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r500867b74f42230a3d65b8aec31fc93ac390eeae737c91a759ab94cb%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-dev] 20210318 CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r5f16a1bd31a7e94ca78eda686179930781aa3a4a990cd55986703581%40%3Cdev.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210318 [jira] [Comment Edited] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r0fbf2c60967bc9f73d7f5a62ad3b955789f9a14b950f42e99fca9b4e%40%3Cissues.hive.apache.org%3E"
            },
            {
              "name": "[hive-issues] 20210729 [jira] [Resolved] (HIVE-24904) CVE-2019-10172,CVE-2019-10202 vulnerabilities in jackson-mapper-asl-1.9.13.jar",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r356592d9874ab4bc9da4754592f8aa6edc894c95e17e58484bc2af7a%40%3Cissues.hive.apache.org%3E"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10202",
        "datePublished": "2019-10-01T14:22:30.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:17:19.913Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10176 (GCVE-0-2019-10176)

    Vulnerability from cvelistv5 – Published: 2019-08-02 13:51 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user's session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack.
    CWE
    References
    URL Tags
    https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2… x_refsource_CONFIRM
    https://access.redhat.com/errata/RHSA-2019:2792 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2019:4053 vendor-advisoryx_refsource_REDHAT
    Impacted products
    Vendor Product Version
    RedHat atomic-openshift Affected: all versions fixed
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:09.971Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10176"
              },
              {
                "name": "RHSA-2019:2792",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:2792"
              },
              {
                "name": "RHSA-2019:4053",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:4053"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "atomic-openshift",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions fixed"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in OpenShift Container Platform, versions 3.11 and later, in which the CSRF tokens used in the cluster console component were found to remain static during a user\u0027s session. An attacker with the ability to observe the value of this token would be able to re-use the token to perform a CSRF attack."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.2,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-352",
                  "description": "CWE-352",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-12-16T17:06:10.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10176"
            },
            {
              "name": "RHSA-2019:2792",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:2792"
            },
            {
              "name": "RHSA-2019:4053",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:4053"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10176",
        "datePublished": "2019-08-02T13:51:09.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:09.971Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10171 (GCVE-0-2019-10171)

    Vulnerability from cvelistv5 – Published: 2019-08-02 13:49 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.
    CWE
    References
    Impacted products
    Vendor Product Version
    RedHat 389-ds-base Affected: 1.4.0.x before 1.4.0.17
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:10.034Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10171"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "389-ds-base",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "1.4.0.x before 1.4.0.17"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-770",
                  "description": "CWE-770",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2020-12-04T18:00:58.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10171"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2019-10171",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "389-ds-base",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "1.4.0.x before 1.4.0.17"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "7.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-770"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10171",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10171"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10171",
        "datePublished": "2019-08-02T13:49:35.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:10.034Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10142 (GCVE-0-2019-10142)

    Vulnerability from cvelistv5 – Published: 2019-07-30 16:26 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    A flaw was found in the Linux kernel's freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw to crash the system, corrupt memory, or create other adverse security affects.
    References
    Impacted products
    Vendor Product Version
    RedHat kernel Affected: 5.0.x up to, excluding 5.0.17
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:10.016Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10142"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "kernel",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.0.x up to, excluding 5.0.17"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in the Linux kernel\u0027s freescale hypervisor manager implementation, kernel versions 5.0.x up to, excluding 5.0.17. A parameter passed to an ioctl was incorrectly validated and used in size calculations for the page size calculation. An attacker can use this flaw to crash the system, corrupt memory, or create other adverse security affects."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-190",
                  "description": "CWE-190",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-119",
                  "description": "CWE-119",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-30T16:26:31.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10142"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10142",
        "datePublished": "2019-07-30T16:26:31.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:10.016Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10141 (GCVE-0-2019-10141)

    Vulnerability from cvelistv5 – Published: 2019-07-30 16:22 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service.
    CWE
    Impacted products
    Vendor Product Version
    RedHat openstack-ironic-inspector Affected: all 5.0.x up to, excluding 5.0.2
    Affected: all 6.0.x up to, excluding 6.0.3
    Affected: all 7.2.x up to, excluding 7.2.4
    Affected: all 8.0.3 up to, excluding 8.0.3
    Affected: 8.2.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:09.963Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rocky"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-stein"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocata"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pike"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queens"
              },
              {
                "name": "RHSA-2019:2505",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:2505"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "openstack-ironic-inspector",
              "vendor": "RedHat",
              "versions": [
                {
                  "status": "affected",
                  "version": "all 5.0.x up to, excluding 5.0.2"
                },
                {
                  "status": "affected",
                  "version": "all 6.0.x up to, excluding 6.0.3"
                },
                {
                  "status": "affected",
                  "version": "all 7.2.x up to, excluding 7.2.4"
                },
                {
                  "status": "affected",
                  "version": "all 8.0.3 up to, excluding 8.0.3"
                },
                {
                  "status": "affected",
                  "version": "8.2.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector\u0027s node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-08-15T16:06:15.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rocky"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-stein"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocata"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pike"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queens"
            },
            {
              "name": "RHSA-2019:2505",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:2505"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2019-10141",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "openstack-ironic-inspector",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "all 5.0.x up to, excluding 5.0.2"
                              },
                              {
                                "version_value": "all 6.0.x up to, excluding 6.0.3"
                              },
                              {
                                "version_value": "all 7.2.x up to, excluding 7.2.4"
                              },
                              {
                                "version_value": "all 8.0.3 up to, excluding 8.0.3"
                              },
                              {
                                "version_value": "8.2.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "RedHat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector\u0027s node_cache.find_node(). This function makes a SQL query using unfiltered data from a server reporting inspection results (by a POST to the /v1/continue endpoint). Because the API is unauthenticated, the flaw could be exploited by an attacker with access to the network on which ironic-inspector is listening. Because of how ironic-inspector uses the query results, it is unlikely that data could be obtained. However, the attacker could pass malicious data and create a denial of service."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "8.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-89"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rocky",
                  "refsource": "MISC",
                  "url": "https://docs.openstack.org/releasenotes/ironic-inspector/rocky.html#relnotes-8-0-3-stable-rocky"
                },
                {
                  "name": "https://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-stein",
                  "refsource": "MISC",
                  "url": "https://docs.openstack.org/releasenotes/ironic-inspector/stein.html#relnotes-8-2-1-stable-stein"
                },
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141",
                  "refsource": "CONFIRM",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10141"
                },
                {
                  "name": "https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocata",
                  "refsource": "MISC",
                  "url": "https://docs.openstack.org/releasenotes/ironic-inspector/ocata.html#relnotes-5-0-2-7-origin-stable-ocata"
                },
                {
                  "name": "https://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pike",
                  "refsource": "MISC",
                  "url": "https://docs.openstack.org/releasenotes/ironic-inspector/pike.html#relnotes-6-0-3-4-stable-pike"
                },
                {
                  "name": "https://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queens",
                  "refsource": "MISC",
                  "url": "https://docs.openstack.org/releasenotes/ironic-inspector/queens.html#relnotes-7-2-4-stable-queens"
                },
                {
                  "name": "RHSA-2019:2505",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2019:2505"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10141",
        "datePublished": "2019-07-30T16:22:59.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:09.963Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10150 (GCVE-0-2019-10150)

    Vulnerability from cvelistv5 – Published: 2019-06-12 13:42 – Updated: 2024-08-04 22:10
    VLAI
    Summary
    It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output.
    CWE
    References
    Impacted products
    Vendor Product Version
    redhat atomic-openshift Affected: 3.6.x - 4.0.0
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:10.023Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150"
              },
              {
                "name": "RHSA-2019:2989",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:2989"
              },
              {
                "name": "RHSA-2019:3007",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:3007"
              },
              {
                "name": "RHSA-2019:3143",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:3143"
              },
              {
                "name": "RHSA-2019:3811",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:3811"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "atomic-openshift",
              "vendor": "redhat",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.6.x - 4.0.0"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "It was found that OpenShift Container Platform versions 3.6.x - 4.6.0 does not perform SSH Host Key checking when using ssh key authentication during builds. An attacker, with the ability to redirect network traffic, could use this to alter the resulting build output."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-11-07T18:06:33.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://docs.openshift.com/container-platform/3.11/dev_guide/builds/build_inputs.html#source-secrets-ssh-key-authentication"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10150"
            },
            {
              "name": "RHSA-2019:2989",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:2989"
            },
            {
              "name": "RHSA-2019:3007",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:3007"
            },
            {
              "name": "RHSA-2019:3143",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:3143"
            },
            {
              "name": "RHSA-2019:3811",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:3811"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10150",
        "datePublished": "2019-06-12T13:42:36.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:10.023Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-15123 (GCVE-0-2017-15123)

    Vulnerability from cvelistv5 – Published: 2019-06-12 13:39 – Updated: 2024-08-05 19:50
    VLAI
    Summary
    A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines.
    CWE
    References
    Impacted products
    Vendor Product Version
    redhat CloudForms Affected: 5.8 - 5.10
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T19:50:16.217Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123"
              },
              {
                "name": "108690",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/108690"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CloudForms",
              "vendor": "redhat",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.8 - 5.10"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A flaw was found in the CloudForms web interface, versions 5.8 - 5.10, where the RSS feed URLs are not properly restricted to authenticated users only. An attacker could use this flaw to view potentially sensitive information from CloudForms including data such as newly created virtual machines."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2019-07-17T13:25:58.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15123"
            },
            {
              "name": "108690",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/108690"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://hacked0x90.wordpress.com/2019/07/17/cve-2017-15123-exploit/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2017-15123",
        "datePublished": "2019-06-12T13:39:34.000Z",
        "dateReserved": "2017-10-08T00:00:00.000Z",
        "dateUpdated": "2024-08-05T19:50:16.217Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2019-10143 (GCVE-0-2019-10143)

    Vulnerability from cvelistv5 – Published: 2019-05-24 00:00 – Updated: 2024-08-04 22:10 Disputed
    VLAI
    Summary
    It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated "there is simply no way for anyone to gain privileges through this alleged issue."
    SSVC
    Exploitation: poc Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-01 19:23 UTC
    Impacted products
    Vendor Product Version
    freeradius freeradius Affected: affects <= 3.0.19
    Create a notification for this product.
    freeradius freeradius Affected: 0 , ≤ 3.0.19 (custom)
        cpe:2.3:a:freeradius:freeradius:*:*:*:*:*:*:*:*
    Create a notification for this product.
    fedoraproject fedora Affected: 30
        cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    Create a notification for this product.
    fedoraproject fedora Affected: 29
        cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
    Create a notification for this product.
    redhat enterprise_linux Affected: 8.0
        cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:freeradius:freeradius:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "freeradius",
                "vendor": "freeradius",
                "versions": [
                  {
                    "lessThanOrEqual": "3.0.19",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fedora",
                "vendor": "fedoraproject",
                "versions": [
                  {
                    "status": "affected",
                    "version": "30"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "fedora",
                "vendor": "fedoraproject",
                "versions": [
                  {
                    "status": "affected",
                    "version": "29"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "8.0"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2019-10143",
                    "options": [
                      {
                        "Exploitation": "poc"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-01T19:23:06.388705Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-01T19:24:21.005Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T22:10:10.031Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "FEDORA-2019-4a8eeaf80e",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/"
              },
              {
                "name": "FEDORA-2019-9454ce61b2",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/"
              },
              {
                "name": "RHSA-2019:3353",
                "tags": [
                  "vendor-advisory",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2019:3353"
              },
              {
                "name": "20191115 [AIT-SA-20191112-01] CVE-2019-10143: Privilege Escalation via Logrotate in FreeRadius",
                "tags": [
                  "mailing-list",
                  "x_transferred"
                ],
                "url": "http://seclists.org/fulldisclosure/2019/Nov/14"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://freeradius.org/security/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.html"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://github.com/FreeRADIUS/freeradius-server/pull/2666"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "freeradius",
              "vendor": "freeradius",
              "versions": [
                {
                  "status": "affected",
                  "version": "affects \u003c= 3.0.19"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the radiusd user. NOTE: the upstream software maintainer has stated \"there is simply no way for anyone to gain privileges through this alleged issue.\""
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 6.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-266",
                  "description": "CWE-266",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-250",
                  "description": "CWE-250",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2023-02-12T00:00:00.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "FEDORA-2019-4a8eeaf80e",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKODLHHUOVAYENTBP4D3N25ST3Q6LJBP/"
            },
            {
              "name": "FEDORA-2019-9454ce61b2",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A6VKBZAZKJP5QKXDXRKCM2ZPZND3TFAX/"
            },
            {
              "name": "RHSA-2019:3353",
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2019:3353"
            },
            {
              "name": "20191115 [AIT-SA-20191112-01] CVE-2019-10143: Privilege Escalation via Logrotate in FreeRadius",
              "tags": [
                "mailing-list"
              ],
              "url": "http://seclists.org/fulldisclosure/2019/Nov/14"
            },
            {
              "url": "https://freeradius.org/security/"
            },
            {
              "url": "http://packetstormsecurity.com/files/155361/FreeRadius-3.0.19-Logrotate-Privilege-Escalation.html"
            },
            {
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10143"
            },
            {
              "url": "https://github.com/FreeRADIUS/freeradius-server/pull/2666"
            }
          ],
          "tags": [
            "disputed"
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2019-10143",
        "datePublished": "2019-05-24T00:00:00.000Z",
        "dateReserved": "2019-03-27T00:00:00.000Z",
        "dateUpdated": "2024-08-04T22:10:10.031Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2016-9586 (GCVE-0-2016-9586)

    Vulnerability from cvelistv5 – Published: 2018-04-23 18:00 – Updated: 2026-04-15 21:03
    VLAI
    Summary
    curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-04-15 21:03 UTC
    CWE
    Impacted products
    Vendor Product Version
    redhat curl Affected: curl 7.52.0
    Create a notification for this product.
    Date Public
    2016-12-21 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-06T02:59:02.246Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2018:3558",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:3558"
              },
              {
                "name": "[debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://curl.haxx.se/docs/adv_20161221A.html"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16"
              },
              {
                "name": "1037515",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1037515"
              },
              {
                "tags": [
                  "x_refsource_CONFIRM",
                  "x_transferred"
                ],
                "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
              },
              {
                "name": "95019",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/95019"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586"
              },
              {
                "name": "GLSA-201701-47",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_GENTOO",
                  "x_transferred"
                ],
                "url": "https://security.gentoo.org/glsa/201701-47"
              },
              {
                "name": "[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"
              },
              {
                "name": "[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
                "tags": [
                  "mailing-list",
                  "x_refsource_MLIST",
                  "x_transferred"
                ],
                "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2016-9586",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-04-15T21:03:41.491637Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-04-15T21:03:48.245Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "curl",
              "vendor": "redhat",
              "versions": [
                {
                  "status": "affected",
                  "version": "curl 7.52.0"
                }
              ]
            }
          ],
          "datePublic": "2016-12-21T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl\u0027s implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-122",
                  "description": "CWE-122",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-06-29T14:06:45.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "name": "RHSA-2018:3558",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:3558"
            },
            {
              "name": "[debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://curl.haxx.se/docs/adv_20161221A.html"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16"
            },
            {
              "name": "1037515",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1037515"
            },
            {
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
            },
            {
              "name": "95019",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/95019"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586"
            },
            {
              "name": "GLSA-201701-47",
              "tags": [
                "vendor-advisory",
                "x_refsource_GENTOO"
              ],
              "url": "https://security.gentoo.org/glsa/201701-47"
            },
            {
              "name": "[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"
            },
            {
              "name": "[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
              "tags": [
                "mailing-list",
                "x_refsource_MLIST"
              ],
              "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2016-9586",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "curl",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "curl 7.52.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "redhat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl\u0027s implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary input filtering, it could allow remote attacks."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "5.9/CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
                    "version": "3.0"
                  }
                ],
                [
                  {
                    "vectorString": "2.6/AV:N/AC:H/Au:N/C:N/I:N/A:P",
                    "version": "2.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-122"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2018:3558",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:3558"
                },
                {
                  "name": "[debian-lts-announce] 20181106 [SECURITY] [DLA 1568-1] curl security update",
                  "refsource": "MLIST",
                  "url": "https://lists.debian.org/debian-lts-announce/2018/11/msg00005.html"
                },
                {
                  "name": "https://curl.haxx.se/docs/adv_20161221A.html",
                  "refsource": "CONFIRM",
                  "url": "https://curl.haxx.se/docs/adv_20161221A.html"
                },
                {
                  "name": "https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16",
                  "refsource": "CONFIRM",
                  "url": "https://github.com/curl/curl/commit/curl-7_51_0-162-g3ab3c16"
                },
                {
                  "name": "1037515",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1037515"
                },
                {
                  "name": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html",
                  "refsource": "CONFIRM",
                  "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
                },
                {
                  "name": "95019",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/95019"
                },
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9586"
                },
                {
                  "name": "GLSA-201701-47",
                  "refsource": "GENTOO",
                  "url": "https://security.gentoo.org/glsa/201701-47"
                },
                {
                  "name": "[bookkeeper-issues] 20210628 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4@%3Cissues.bookkeeper.apache.org%3E"
                },
                {
                  "name": "[bookkeeper-issues] 20210629 [GitHub] [bookkeeper] padma81 opened a new issue #2746: Security Vulnerabilities in CentOS 7 image, Upgrade image to CentOS 8",
                  "refsource": "MLIST",
                  "url": "https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b@%3Cissues.bookkeeper.apache.org%3E"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2016-9586",
        "datePublished": "2018-04-23T18:00:00.000Z",
        "dateReserved": "2016-11-23T00:00:00.000Z",
        "dateUpdated": "2026-04-15T21:03:48.245Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2018-1086 (GCVE-0-2018-1086)

    Vulnerability from cvelistv5 – Published: 2018-04-12 16:00 – Updated: 2024-08-05 03:51
    VLAI
    Summary
    pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege.
    CWE
    References
    URL Tags
    https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2018:1060 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2018:1927 vendor-advisoryx_refsource_REDHAT
    https://www.debian.org/security/2018/dsa-4169 vendor-advisoryx_refsource_DEBIAN
    Impacted products
    Vendor Product Version
    redhat pcs Affected: pcs 0.9.164
    Affected: pcs 0.10
    Create a notification for this product.
    Date Public
    2018-04-12 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T03:51:48.471Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086"
              },
              {
                "name": "RHSA-2018:1060",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:1060"
              },
              {
                "name": "RHSA-2018:1927",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2018:1927"
              },
              {
                "name": "DSA-4169",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_DEBIAN",
                  "x_transferred"
                ],
                "url": "https://www.debian.org/security/2018/dsa-4169"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "pcs",
              "vendor": "redhat",
              "versions": [
                {
                  "status": "affected",
                  "version": "pcs 0.9.164"
                },
                {
                  "status": "affected",
                  "version": "pcs 0.10"
                }
              ]
            }
          ],
          "datePublic": "2018-04-12T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                "version": "3.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2018-06-19T09:57:01.000Z",
            "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
            "shortName": "redhat"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086"
            },
            {
              "name": "RHSA-2018:1060",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:1060"
            },
            {
              "name": "RHSA-2018:1927",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2018:1927"
            },
            {
              "name": "DSA-4169",
              "tags": [
                "vendor-advisory",
                "x_refsource_DEBIAN"
              ],
              "url": "https://www.debian.org/security/2018/dsa-4169"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "secalert@redhat.com",
              "ID": "CVE-2018-1086",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "pcs",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "pcs 0.9.164"
                              },
                              {
                                "version_value": "pcs 0.10"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "redhat"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "pcs before versions 0.9.164 and 0.10 is vulnerable to a debug parameter removal bypass. REST interface of the pcsd service did not properly remove the pcs debug argument from the /run_pcs query, possibly disclosing sensitive information. A remote attacker with a valid token could use this flaw to elevate their privilege."
                }
              ]
            },
            "impact": {
              "cvss": [
                [
                  {
                    "vectorString": "4.3/CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
                    "version": "3.0"
                  }
                ]
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-20"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086",
                  "refsource": "MISC",
                  "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1086"
                },
                {
                  "name": "RHSA-2018:1060",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:1060"
                },
                {
                  "name": "RHSA-2018:1927",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2018:1927"
                },
                {
                  "name": "DSA-4169",
                  "refsource": "DEBIAN",
                  "url": "https://www.debian.org/security/2018/dsa-4169"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "assignerShortName": "redhat",
        "cveId": "CVE-2018-1086",
        "datePublished": "2018-04-12T16:00:00.000Z",
        "dateReserved": "2017-12-04T00:00:00.000Z",
        "dateUpdated": "2024-08-05T03:51:48.471Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2017-1000253 (GCVE-0-2017-1000253)

    Vulnerability from cvelistv5 – Published: 2017-10-04 01:00 – Updated: 2025-10-21 23:55
    VLAI
    Summary
    Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm->mmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm->mmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm->mmap_base into the are that is supposed to be the "gap" between the stack and the binary.
    SSVC
    Exploitation: active Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 03:55 UTC
    CWE
    • n/a
    • CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer
    References
    URL Tags
    https://access.redhat.com/errata/RHSA-2017:2798 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2795 vendor-advisoryx_refsource_REDHAT
    http://www.securitytracker.com/id/1039434 vdb-entryx_refsource_SECTRACK
    https://access.redhat.com/errata/RHSA-2017:2801 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2796 vendor-advisoryx_refsource_REDHAT
    http://www.securityfocus.com/bid/101010 vdb-entryx_refsource_BID
    https://access.redhat.com/errata/RHSA-2017:2799 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2794 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2793 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2797 vendor-advisoryx_refsource_REDHAT
    https://access.redhat.com/errata/RHSA-2017:2802 vendor-advisoryx_refsource_REDHAT
    https://www.qualys.com/2017/09/26/cve-2017-100025… x_refsource_MISC
    https://access.redhat.com/errata/RHSA-2017:2800 vendor-advisoryx_refsource_REDHAT
    https://www.cisa.gov/known-exploited-vulnerabilit… government-resource
    Impacted products
    Vendor Product Version
    centos centos Affected: 6.0
        cpe:2.3:o:centos:centos:6.0:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.1
        cpe:2.3:o:centos:centos:6.1:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.2
        cpe:2.3:o:centos:centos:6.2:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.3
        cpe:2.3:o:centos:centos:6.3:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.4
        cpe:2.3:o:centos:centos:6.4:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.5
        cpe:2.3:o:centos:centos:6.5:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.6
        cpe:2.3:o:centos:centos:6.6:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.7
        cpe:2.3:o:centos:centos:6.7:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.8
        cpe:2.3:o:centos:centos:6.8:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 6.9
        cpe:2.3:o:centos:centos:6.9:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 7.1406
        cpe:2.3:o:centos:centos:7.1406:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 7.1503
        cpe:2.3:o:centos:centos:7.1503:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 7.1511
        cpe:2.3:o:centos:centos:7.1511:*:*:*:*:*:*:*
    Create a notification for this product.
    centos centos Affected: 7.1611
        cpe:2.3:o:centos:centos:7.1611:*:*:*:*:*:*:*
    Create a notification for this product.
    redhat enterprise_linux Affected: 6.0
    Affected: 6.1
    Affected: 6.2
    Affected: 6.3
    Affected: 6.4
    Affected: 6.5
    Affected: 6.6
    Affected: 6.7
    Affected: 6.8
    Affected: 6.9
    Affected: 7.0
    Affected: 7.1
    Affected: 7.2
    Affected: 7.3
        cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*
        cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*
    Create a notification for this product.
    linux linux_kernel Affected: 2.6.25 , < 3.2.70 (custom)
    Affected: 3.3 , < 3.4.109 (custom)
    Affected: 3.5 , < 3.10.77 (custom)
    Affected: 3.11 , < 3.12.43 (custom)
    Affected: 3.13 , < 3.14.41 (custom)
    Affected: 3.15 , < 3.16.35 (custom)
    Affected: 3.17 , < 3.18.14 (custom)
    Affected: 3.19 , < 3.19.7 (custom)
    Affected: 1.0 , < 4.0.2 (custom)
        cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2017-10-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-05T22:00:39.693Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "RHSA-2017:2798",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2798"
              },
              {
                "name": "RHSA-2017:2795",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2795"
              },
              {
                "name": "1039434",
                "tags": [
                  "vdb-entry",
                  "x_refsource_SECTRACK",
                  "x_transferred"
                ],
                "url": "http://www.securitytracker.com/id/1039434"
              },
              {
                "name": "RHSA-2017:2801",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2801"
              },
              {
                "name": "RHSA-2017:2796",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2796"
              },
              {
                "name": "101010",
                "tags": [
                  "vdb-entry",
                  "x_refsource_BID",
                  "x_transferred"
                ],
                "url": "http://www.securityfocus.com/bid/101010"
              },
              {
                "name": "RHSA-2017:2799",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2799"
              },
              {
                "name": "RHSA-2017:2794",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2794"
              },
              {
                "name": "RHSA-2017:2793",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2793"
              },
              {
                "name": "RHSA-2017:2797",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2797"
              },
              {
                "name": "RHSA-2017:2802",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2802"
              },
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt"
              },
              {
                "name": "RHSA-2017:2800",
                "tags": [
                  "vendor-advisory",
                  "x_refsource_REDHAT",
                  "x_transferred"
                ],
                "url": "https://access.redhat.com/errata/RHSA-2017:2800"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.2:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.2"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.4:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.4"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.5:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.5"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.6:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.6"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.7:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.7"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.8:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.8"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:6.9:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.9"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:7.1406:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1406"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:7.1503:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1503"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:7.1511:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1511"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:centos:centos:7.1611:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "centos",
                "vendor": "centos",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1611"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.3:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.4:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.5:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.6:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.8:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:6.9:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.1:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.2:*:*:*:*:*:*:*",
                  "cpe:2.3:o:redhat:enterprise_linux:7.3:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "enterprise_linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.0"
                  },
                  {
                    "status": "affected",
                    "version": "6.1"
                  },
                  {
                    "status": "affected",
                    "version": "6.2"
                  },
                  {
                    "status": "affected",
                    "version": "6.3"
                  },
                  {
                    "status": "affected",
                    "version": "6.4"
                  },
                  {
                    "status": "affected",
                    "version": "6.5"
                  },
                  {
                    "status": "affected",
                    "version": "6.6"
                  },
                  {
                    "status": "affected",
                    "version": "6.7"
                  },
                  {
                    "status": "affected",
                    "version": "6.8"
                  },
                  {
                    "status": "affected",
                    "version": "6.9"
                  },
                  {
                    "status": "affected",
                    "version": "7.0"
                  },
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "status": "affected",
                    "version": "7.2"
                  },
                  {
                    "status": "affected",
                    "version": "7.3"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux_kernel",
                "vendor": "linux",
                "versions": [
                  {
                    "lessThan": "3.2.70",
                    "status": "affected",
                    "version": "2.6.25",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.4.109",
                    "status": "affected",
                    "version": "3.3",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.10.77",
                    "status": "affected",
                    "version": "3.5",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.12.43",
                    "status": "affected",
                    "version": "3.11",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.14.41",
                    "status": "affected",
                    "version": "3.13",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.16.35",
                    "status": "affected",
                    "version": "3.15",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.18.14",
                    "status": "affected",
                    "version": "3.17",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "3.19.7",
                    "status": "affected",
                    "version": "3.19",
                    "versionType": "custom"
                  },
                  {
                    "lessThan": "4.0.2",
                    "status": "affected",
                    "version": "1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2017-1000253",
                    "options": [
                      {
                        "Exploitation": "active"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T03:55:15.715774Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              },
              {
                "other": {
                  "content": {
                    "dateAdded": "2024-09-09",
                    "reference": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000253"
                  },
                  "type": "kev"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-119",
                    "description": "CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-10-21T23:55:32.192Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "references": [
              {
                "tags": [
                  "government-resource"
                ],
                "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000253"
              }
            ],
            "timeline": [
              {
                "lang": "en",
                "time": "2024-09-09T00:00:00.000Z",
                "value": "CVE-2017-1000253 added to CISA KEV"
              }
            ],
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "dateAssigned": "2017-09-25T00:00:00.000Z",
          "datePublic": "2017-10-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm-\u003emmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm-\u003emmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm-\u003emmap_base into the are that is supposed to be the \"gap\" between the stack and the binary."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2017-12-08T10:57:01.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "name": "RHSA-2017:2798",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2798"
            },
            {
              "name": "RHSA-2017:2795",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2795"
            },
            {
              "name": "1039434",
              "tags": [
                "vdb-entry",
                "x_refsource_SECTRACK"
              ],
              "url": "http://www.securitytracker.com/id/1039434"
            },
            {
              "name": "RHSA-2017:2801",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2801"
            },
            {
              "name": "RHSA-2017:2796",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2796"
            },
            {
              "name": "101010",
              "tags": [
                "vdb-entry",
                "x_refsource_BID"
              ],
              "url": "http://www.securityfocus.com/bid/101010"
            },
            {
              "name": "RHSA-2017:2799",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2799"
            },
            {
              "name": "RHSA-2017:2794",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2794"
            },
            {
              "name": "RHSA-2017:2793",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2793"
            },
            {
              "name": "RHSA-2017:2797",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2797"
            },
            {
              "name": "RHSA-2017:2802",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2802"
            },
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt"
            },
            {
              "name": "RHSA-2017:2800",
              "tags": [
                "vendor-advisory",
                "x_refsource_REDHAT"
              ],
              "url": "https://access.redhat.com/errata/RHSA-2017:2800"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "DATE_ASSIGNED": "2017-09-25",
              "ID": "CVE-2017-1000253",
              "REQUESTER": "qsa@qualys.com",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (committed on April 14, 2015). This kernel vulnerability was fixed in April 2015 by commit a87938b2e246b81b4fb713edb371a9fa3c5c3c86 (backported to Linux 3.10.77 in May 2015), but it was not recognized as a security threat. With CONFIG_ARCH_BINFMT_ELF_RANDOMIZE_PIE enabled, and a normal top-down address allocation strategy, load_elf_binary() will attempt to map a PIE binary into an address range immediately below mm-\u003emmap_base. Unfortunately, load_elf_ binary() does not take account of the need to allocate sufficient space for the entire binary which means that, while the first PT_LOAD segment is mapped below mm-\u003emmap_base, the subsequent PT_LOAD segment(s) end up being mapped above mm-\u003emmap_base into the are that is supposed to be the \"gap\" between the stack and the binary."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "RHSA-2017:2798",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2798"
                },
                {
                  "name": "RHSA-2017:2795",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2795"
                },
                {
                  "name": "1039434",
                  "refsource": "SECTRACK",
                  "url": "http://www.securitytracker.com/id/1039434"
                },
                {
                  "name": "RHSA-2017:2801",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2801"
                },
                {
                  "name": "RHSA-2017:2796",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2796"
                },
                {
                  "name": "101010",
                  "refsource": "BID",
                  "url": "http://www.securityfocus.com/bid/101010"
                },
                {
                  "name": "RHSA-2017:2799",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2799"
                },
                {
                  "name": "RHSA-2017:2794",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2794"
                },
                {
                  "name": "RHSA-2017:2793",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2793"
                },
                {
                  "name": "RHSA-2017:2797",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2797"
                },
                {
                  "name": "RHSA-2017:2802",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2802"
                },
                {
                  "name": "https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt",
                  "refsource": "MISC",
                  "url": "https://www.qualys.com/2017/09/26/cve-2017-1000253/cve-2017-1000253.txt"
                },
                {
                  "name": "RHSA-2017:2800",
                  "refsource": "REDHAT",
                  "url": "https://access.redhat.com/errata/RHSA-2017:2800"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-2017-1000253",
        "datePublished": "2017-10-04T01:00:00.000Z",
        "dateReserved": "2017-10-03T00:00:00.000Z",
        "dateUpdated": "2025-10-21T23:55:32.192Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-1999-0043 (GCVE-0-1999-0043)

    Vulnerability from cvelistv5 – Published: 1999-09-29 04:00 – Updated: 2024-08-01 20:03
    VLAI
    Summary
    Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-01 19:56 UTC
    CWE
    • n/a
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    References
    Impacted products
    Vendor Product Version
    isc inn Affected: 1.4sec
    Affected: 1.4sec2
    Affected: 1.4unoff3
    Affected: 1.4unoff4
    Affected: 1.5
        cpe:2.3:a:isc:inn:1.4sec:*:*:*:*:*:*:*
        cpe:2.3:a:isc:inn:1.4sec2:*:*:*:*:*:*:*
        cpe:2.3:a:isc:inn:1.4unoff3:*:*:*:*:*:*:*
        cpe:2.3:a:isc:inn:1.4unoff4:*:*:*:*:*:*:*
        cpe:2.3:a:isc:inn:1.5:*:*:*:*:*:*:*
    Create a notification for this product.
    netscape news_server Affected: 1.1
        cpe:2.3:a:netscape:news_server:1.1:*:*:*:*:*:*:*
    Create a notification for this product.
    bsdi bsd_os Affected: 2.1
        cpe:2.3:o:bsdi:bsd_os:2.1:*:*:*:*:*:*:*
    Create a notification for this product.
    caldera openlinux Affected: 1.0
        cpe:2.3:o:caldera:openlinux:1.0:*:*:*:*:*:*:*
    Create a notification for this product.
    redhat linux Affected: 4.0
        cpe:2.3:o:redhat:linux:4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    redhat linux Affected: 4.1
        cpe:2.3:o:redhat:linux:4.1:*:*:*:*:*:*:*
    Create a notification for this product.
    nec goah_intrasv Affected: 1.1
        cpe:2.3:h:nec:goah_intrasv:1.1:*:*:*:*:*:*:*
    Create a notification for this product.
    nec goah_networksv Affected: 1.2
    Affected: 2.2
    Affected: 3.1
        cpe:2.3:h:nec:goah_networksv:1.2:*:*:*:*:*:*:*
        cpe:2.3:h:nec:goah_networksv:2.2:*:*:*:*:*:*:*
        cpe:2.3:h:nec:goah_networksv:3.1:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T16:27:57.295Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:isc:inn:1.4sec:*:*:*:*:*:*:*",
                  "cpe:2.3:a:isc:inn:1.4sec2:*:*:*:*:*:*:*",
                  "cpe:2.3:a:isc:inn:1.4unoff3:*:*:*:*:*:*:*",
                  "cpe:2.3:a:isc:inn:1.4unoff4:*:*:*:*:*:*:*",
                  "cpe:2.3:a:isc:inn:1.5:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "inn",
                "vendor": "isc",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.4sec"
                  },
                  {
                    "status": "affected",
                    "version": "1.4sec2"
                  },
                  {
                    "status": "affected",
                    "version": "1.4unoff3"
                  },
                  {
                    "status": "affected",
                    "version": "1.4unoff4"
                  },
                  {
                    "status": "affected",
                    "version": "1.5"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:netscape:news_server:1.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "news_server",
                "vendor": "netscape",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:bsdi:bsd_os:2.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "bsd_os",
                "vendor": "bsdi",
                "versions": [
                  {
                    "status": "affected",
                    "version": "2.1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:caldera:openlinux:1.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "openlinux",
                "vendor": "caldera",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:linux:4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.0"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:redhat:linux:4.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "linux",
                "vendor": "redhat",
                "versions": [
                  {
                    "status": "affected",
                    "version": "4.1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:nec:goah_intrasv:1.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "goah_intrasv",
                "vendor": "nec",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.1"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:h:nec:goah_networksv:1.2:*:*:*:*:*:*:*",
                  "cpe:2.3:h:nec:goah_networksv:2.2:*:*:*:*:*:*:*",
                  "cpe:2.3:h:nec:goah_networksv:3.1:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "goah_networksv",
                "vendor": "nec",
                "versions": [
                  {
                    "status": "affected",
                    "version": "1.2"
                  },
                  {
                    "status": "affected",
                    "version": "2.2"
                  },
                  {
                    "status": "affected",
                    "version": "3.1"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-1999-0043",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-01T19:56:17.928328Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-78",
                    "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-01T20:03:35.981Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "n/a",
              "vendor": "n/a",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Command execution via shell metachars in INN daemon (innd) 1.5 using \"newgroup\" and \"rmgroup\" control messages, and others."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "n/a",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-17T06:31:06.000Z",
            "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
            "shortName": "mitre"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043"
            }
          ],
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "cve@mitre.org",
              "ID": "CVE-1999-0043",
              "STATE": "PUBLIC"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "n/a",
                          "version": {
                            "version_data": [
                              {
                                "version_value": "n/a"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "n/a"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "Command execution via shell metachars in INN daemon (innd) 1.5 using \"newgroup\" and \"rmgroup\" control messages, and others."
                }
              ]
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "n/a"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043",
                  "refsource": "MISC",
                  "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0043"
                }
              ]
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "assignerShortName": "mitre",
        "cveId": "CVE-1999-0043",
        "datePublished": "1999-09-29T04:00:00.000Z",
        "dateReserved": "1999-06-07T00:00:00.000Z",
        "dateUpdated": "2024-08-01T20:03:35.981Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }