Redhat Fuse vulnerabilities
40 known vulnerabilities affecting redhat/fuse.
Total CVEs
40
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
3
Severity breakdown
CRITICAL8HIGH13MEDIUM11LOW8
Vulnerabilities
Page 1 of 2
CVE-2015-1427P1CRITICALCVSS 9.8KEVPoCRansomwarev1.0.02015-02-17
CVE-2015-1427 [CRITICAL] CVE-2015-1427: The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attac
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
nvd
CVE-2016-4437P1CRITICALCVSS 9.8KEVPoCv1.02016-06-07
CVE-2016-4437 [CRITICAL] CWE-321 CVE-2016-4437: Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature,
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
nvd
CVE-2017-12617P1HIGHCVSS 8.1KEVPoCv1.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-5645P1CRITICALCVSS 9.8PoCv1.02017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2018-1270P2CRITICALCVSS 9.8v1.0.02018-04-06
CVE-2018-1270 [CRITICAL] CWE-94 CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution
nvd
CVE-2026-28367P2CRITICALCVSS 9.1v7.0.02026-03-27
CVE-2026-28367 [CRITICAL] CWE-444 CVE-2026-28367: A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` a
A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, potentially leading to unauthorized access or manipul
nvd
CVE-2018-10906P3HIGHCVSS 7.8PoC≥ 0, < 2.9.8-12018-07-24
CVE-2018-10906 [HIGH] CVE-2018-10906: In fuse before versions 2
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, po
osv
CVE-2026-28368P2CRITICALCVSS 9.1v7.0.02026-03-27
CVE-2026-28368 [CRITICAL] CWE-444 CVE-2026-28368: A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially cra
A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, potentially bypassing security controls and accessing u
nvd
CVE-2026-28369P2CRITICALCVSS 9.1v7.0.02026-03-27
CVE-2026-28369 [CRITICAL] CWE-444 CVE-2026-28369: A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line sta
A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform request smuggling. Request smuggling allows an attack
nvd
CVE-2010-3879P3LOWCVSS 3.3PoC≥ 0, < 2.8.5-12011-01-22
CVE-2010-3879 [LOW] CVE-2010-3879: FUSE, possibly 2
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.
osv
CVE-2025-12543P3CRITICALCVSS 9.6v7.0.02026-01-07
CVE-2025-12543 [CRITICAL] CWE-20 CVE-2025-12543: A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Ja
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perf
nvd
CVE-2018-1258P3HIGHCVSS 8.8v7.3.02018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2026-41731P3HIGHCVSS 8.1v7.0.02026-06-10
CVE-2026-41731 [HIGH] CWE-502 CVE-2026-41731: JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize ar
nvd
CVE-2019-10174P3HIGHCVSS 8.8v1.02019-11-25
CVE-2019-10174 [HIGH] CWE-470 CVE-2019-10174: A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
nvd
CVE-2025-9784P3HIGHCVSS 7.5v7.0.02025-09-02
CVE-2025-9784 [HIGH] CWE-770 CVE-2025-9784: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets w
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implem
nvd
CVE-2024-1635P3HIGHCVSS 7.5v1.02024-02-19
CVE-2024-1635 [HIGH] CWE-400 CVE-2024-1635: A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the
nvd
CVE-2019-0204P3HIGHCVSS 7.8v7.5.02019-03-25
CVE-2019-0204 [HIGH] CVE-2019-0204: A specifically crafted Docker image running under the root user can overwrite the init helper binary
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, and 1.7.0 to 1.7.1. A malicious actor can therefore gain root-level code execution on the host.
nvd
CVE-2015-3202P4LOWCVSS 3.6PoC≥ 0, < 2.9.3-162015-07-02
CVE-2015-3202 [LOW] CVE-2015-3202: fusermount in FUSE before 2
fusermount in FUSE before 2.9.3-15 does not properly clear the environment before invoking (1) mount or (2) umount as root, which allows local users to write to arbitrary files via a crafted LIBMOUNT_MTAB environment variable that is used by mount's debugging feature.
osv
CVE-2019-0201P3MEDIUMCVSS 5.9v1.0.02019-05-23
CVE-2019-0201 [MEDIUM] CWE-862 CVE-2019-0201: An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s g
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is use
nvd
CVE-2019-14900P3MEDIUMCVSS 6.5fixed in 7.8.02020-07-06
CVE-2019-14900 [MEDIUM] CWE-89 CVE-2019-14900: A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection
A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or GROUP BY parts of the query. This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks
nvd
1 / 2Next →