threat
engine
.sh
Back
·
··:··
Home
/
Product
/
redhat integration camel k
Product
redhat integration camel k
20 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-7885
all versions
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple r
7.5
HIGH
CVE-2023-44487
all versions
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5
HIGH
CVE-2022-4245
< 1.10.1
A flaw was found in codehaus-plexus. The org.codehaus.plexus.util.xml.XmlWriterUtil#writeComment fails to sanitize comments for a
4.3
MEDIUM
CVE-2022-4244
< 1.10.1
A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and direct
7.5
HIGH
CVE-2023-4853
< 1.10.2
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when acceptin
8.1
HIGH
CVE-2023-1108
all versions
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status update
7.5
HIGH
CVE-2022-41862
all versions
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport e
3.7
LOW
CVE-2022-4492
all versions
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compul
7.5
HIGH
CVE-2022-1278
all versions
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may conta
7.5
HIGH
CVE-2022-2764
all versions
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invoca
4.9
MEDIUM
CVE-2022-1259
all versions
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or
7.5
HIGH
CVE-2022-0084
all versions
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to ano
7.5
HIGH
CVE-2021-4178
all versions
A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an i
6.7
MEDIUM
CVE-2021-3690
all versions
A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows
7.5
HIGH
CVE-2022-2053
all versions
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequest
7.5
HIGH
CVE-2021-4104
all versions
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j config
7.5
HIGH
CVE-2021-3642
all versions
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where Scra
5.3
MEDIUM
CVE-2020-14326
all versions
A vulnerability was found in RESTEasy, where RootNode incorrectly caches routes. This issue results in hash flooding, leading to s
7.5
HIGH
CVE-2021-3536
all versions
A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin console, it is
4.8
MEDIUM
CVE-2021-20218
all versions
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause
7.4
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin