cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 6 of 11
CVE-2017-10378P3MEDIUMCVSS 6.5v122017-10-19
CVE-2017-10378 [MEDIUM] CVE-2017-10378: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.11 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of thi
nvd
CVE-2018-2819P3MEDIUMCVSS 6.5v122018-04-19
CVE-2018-2819 [MEDIUM] CVE-2018-2819: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versio Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2018-2817P3MEDIUMCVSS 6.5v122018-04-19
CVE-2018-2817 [MEDIUM] CVE-2018-2817: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2014-0071P3MEDIUMCVSS 6.4v4.02014-04-17
CVE-2014-0071 [MEDIUM] CWE-264 CVE-2014-0071: PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neu PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
nvd
CVE-2017-8309P4HIGHCVSS 7.5v6.0v7.0+4 more2017-05-23
CVE-2017-8309 [HIGH] CWE-772 CVE-2017-8309: Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a den Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memory consumption) by repeatedly starting and stopping audio capture.
nvd
CVE-2013-6470P3MEDIUMCVSS 5.0v4.02014-06-02
CVE-2013-6470 [MEDIUM] CWE-287 CVE-2013-6470: The default configuration in the standalone controller quickstack manifest in openstack-foreman-inst The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v132018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2017-10384P4MEDIUMCVSS 6.5v122017-10-19
CVE-2017-10384 [MEDIUM] CVE-2017-10384: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.57 and earlier 5.6.37 and earlier 5.7.19 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2018-14635P4MEDIUMCVSS 6.5v10v12+1 more2018-09-10
CVE-2018-14635 [MEDIUM] CWE-20 CVE-2018-14635: When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports w When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of opensta
nvd
CVE-2013-4222P4MEDIUMCVSS 6.5v3.02013-09-30
CVE-2013-4222 [MEDIUM] CWE-522 CVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
nvd
CVE-2019-14856P4MEDIUMCVSS 6.5v132019-11-26
CVE-2019-14856 [MEDIUM] CWE-287 CVE-2019-14856: ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
nvd
CVE-2020-10753P4MEDIUMCVSS 6.5v152020-06-26
CVE-2020-10753 [MEDIUM] CWE-113 CVE-2020-10753: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is rel A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are v
nvd
CVE-2013-6391P4MEDIUMCVSS 5.8v4.02013-12-14
CVE-2013-6391 [MEDIUM] CWE-269 CVE-2013-6391: The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehou The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.
nvd
CVE-2016-2857P4HIGHCVSS 8.4v5.0v6.0+3 more2016-04-12
CVE-2016-2857 [HIGH] CWE-119 CVE-2016-2857: The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
nvd
CVE-2022-3100P3MEDIUMCVSS 5.9v13v16.1+2 more2023-01-18
CVE-2022-3100 [MEDIUM] CWE-305 CVE-2022-3100: A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
nvd
CVE-2018-2761P4MEDIUMCVSS 5.9v122018-04-19
CVE-2018-2761 [MEDIUM] CVE-2018-2761: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2022-1655P4MEDIUMCVSS 6.5v16.2vOpenStack 16.22022-07-22
CVE-2022-1655 [MEDIUM] CWE-732 CVE-2022-1655: An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenSt An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite HorizonSecureCookies being set to true in the environmental files, possibly leading to a loss of confidentiality and integrity.
nvd
CVE-2020-1759P4MEDIUMCVSS 6.8v152020-04-13
CVE-2020-1759 [MEDIUM] CWE-323 CVE-2020-1759: A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 wher A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a
nvd
CVE-2020-14364P4MEDIUMCVSS 5.0v10v132020-08-31
CVE-2020-14364 [MEDIUM] CWE-125 CVE-2020-14364: An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[4096]' in the do_token_in, do_token_out routines. This flaw allows a guest user to crash the QEMU process, resulting in a denial of se
nvd
CVE-2016-9590P4MEDIUMCVSS 6.5v8v9+1 more2018-04-26
CVE-2016-9590 [MEDIUM] CWE-200 CVE-2016-9590: puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat Open puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
nvd
Redhat Openstack vulnerabilities | cvebase