cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 3 of 11
CVE-2019-14859P3CRITICALCVSS 9.1v10v13+2 more2020-01-02
CVE-2019-14859 [CRITICAL] CWE-347 CVE-2019-14859: A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify wheth A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
nvd
CVE-2018-1000807P3HIGHCVSS 8.1v132018-10-08
CVE-2018-1000807 [HIGH] CWE-416 CVE-2018-1000807: Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use Aft Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a referen
nvd
CVE-2016-3710P3HIGHCVSS 8.8v5.0v6.0+2 more2016-05-11
CVE-2016-3710 [HIGH] CWE-119 CVE-2016-3710: The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which a The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
nvd
CVE-2016-4474P3HIGHCVSS 8.8v7.0v82016-06-30
CVE-2016-4474 [HIGH] CWE-200 CVE-2016-4474: The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) directo The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which allows attackers to gain access via unspecified vectors.
nvd
CVE-2021-3656P3HIGHCVSS 8.8v132022-03-04
CVE-2021-3656 [HIGH] CWE-862 CVE-2021-3656: A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs whe A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS
nvd
CVE-2020-25717P3HIGHCVSS 8.1v13v16.1+1 more2022-02-18
CVE-2020-25717 [HIGH] CWE-20 CVE-2020-25717: A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
nvd
CVE-2016-1714P3HIGHCVSS 8.1v5.02016-04-07
CVE-2016-1714 [HIGH] CWE-119 CVE-2016-1714: The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when bui The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute arbitrary code via an invalid curren
nvd
CVE-2018-14620P3CRITICALCVSS 9.8v12v132018-09-10
CVE-2018-14620 [CRITICAL] CWE-494 CVE-2018-14620: The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HT The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant container image. Version of openstack-rabbitmq-container and openstack-containers as shipped with Red Hat O
nvd
CVE-2013-4386P3HIGHCVSS 7.5v3.02013-11-20
CVE-2013-4386 [HIGH] CWE-89 CVE-2013-4386: Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.
nvd
CVE-2017-7539P3HIGHCVSS 7.5v6.0v7.0+4 more2018-07-26
CVE-2017-7539 [HIGH] CWE-617 CVE-2017-7539: An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server' An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected data during connection negotiation. A remote user or process could use this flaw to crash the qemu-nbd server resulti
nvd
CVE-2018-10898P3HIGHCVSS 8.8v132018-07-30
CVE-2018-10898 [HIGH] CWE-798 CVE-2018-10898: A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.
nvd
CVE-2018-10903P3HIGHCVSS 7.5v132018-07-30
CVE-2018-10903 [HIGH] CWE-20 CVE-2018-10903: A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they would have a 1 in 256 chance of passi
nvd
CVE-2016-4985P3HIGHCVSS 7.5v7.0v82016-07-12
CVE-2016-4985 [HIGH] CWE-200 CVE-2016-4985: The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allo The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.
nvd
CVE-2019-3895P3HIGHCVSS 8.0v122019-06-03
CVE-2019-3895 [HIGH] CWE-284 CVE-2019-3895: An access-control flaw was found in the Octavia service when the cloud platform was deployed using R An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compr
nvd
CVE-2015-5329P3HIGHCVSS 7.3v7.02016-04-11
CVE-2015-5329 [HIGH] CWE-264 CVE-2015-5329: The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack P The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.
nvd
CVE-2019-11287P3HIGHCVSS 7.5v152019-11-23
CVE-2019-11287 [HIGH] CWE-400 CVE-2019-11287: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that w
nvd
CVE-2017-9214P3CRITICALCVSS 9.8v6.0v7.0+4 more2017-05-23
CVE-2017-9214 [CRITICAL] CWE-191 CVE-2017-9214: In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, ther In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-read that is caused by an unsigned integer underflow in the function `ofputil_pull_queue_get_config_reply10` in `lib/ofp-util.c`.
nvd
CVE-2019-16786P3HIGHCVSS 7.5v152019-12-20
CVE-2019-16786 [HIGH] CWE-444 CVE-2019-16786: Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single s Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding first, followed by any further tr
nvd
CVE-2017-2673P3HIGHCVSS 7.2v9v102018-07-19
CVE-2017-2673 [HIGH] CWE-863 CVE-2017-2673: An authorization-check flaw was discovered in federation configurations of the OpenStack Identity se An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and unintentionally be granted all related roles including administrative roles.
nvd
CVE-2016-9599P3HIGHCVSS 7.5v102018-04-24
CVE-2016-9599 [HIGH] CWE-284 CVE-2016-9599: puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these open ports to gain access to unauthorized resources.
nvd
Redhat Openstack vulnerabilities | cvebase