cbcvebase.

Redhat Openstack vulnerabilities

208 known vulnerabilities affecting redhat/openstack.

Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11

Vulnerabilities

Page 7 of 11
CVE-2017-7543P4MEDIUMCVSS 5.9v6.0v7.0+4 more2018-07-26
CVE-2017-7543 [MEDIUM] CWE-362 CVE-2017-7543: A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0: net.bridge.bridge-nf-call-ip6tables and net.bridge.bridge-nf-call-iptables. T
nvd
CVE-2013-2882P4HIGHCVSS 7.5v3.02013-07-31
CVE-2013-2882 [HIGH] CWE-843 CVE-2013-2882: Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial o Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
nvd
CVE-2015-5225P4HIGHCVSS 7.2v5.0v6.0+1 more2015-11-06
CVE-2015-5225 [HIGH] CWE-119 CVE-2015-5225: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
nvd
CVE-2018-7536P4MEDIUMCVSS 5.3v10v132018-03-09
CVE-2018-7536 [MEDIUM] CWE-185 CVE-2018-7536: An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The An issue was discovered in Django 2.0 before 2.0.3, 1.11 before 1.11.11, and 1.8 before 1.8.19. The django.utils.html.urlize() function was extremely slow to evaluate certain inputs due to catastrophic backtracking vulnerabilities in two regular expressions (only one regular expression for Django 1.8.x). The urlize() function is used to implement the u
nvd
CVE-2018-10855P4MEDIUMCVSS 5.9v13v10+1 more2018-07-03
CVE-2018-10855 [MEDIUM] CWE-532 CVE-2018-10855: Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tas Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect sensitive data passed to a task from being logged, and that task does not run successfully, Ansible will expose sensitive data in log files and on the terminal of the user running Ansible.
nvd
CVE-2018-14432P4MEDIUMCVSS 5.3v10v12+1 more2018-07-31
CVE-2018-14432 [MEDIUM] CWE-200 CVE-2018-14432: In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticate In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Key
nvd
CVE-2020-10711P4MEDIUMCVSS 5.9v132020-05-22
CVE-2020-10711 [MEDIUM] CWE-476 CVE-2020-10711: A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO restricted bitmap tag in the 'cipso_v4_p
nvd
CVE-2020-1758P4MEDIUMCVSS 5.9v102020-05-15
CVE-2020-1758 [MEDIUM] CWE-297 CVE-2020-1758: A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname v A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
nvd
CVE-2019-10156P4MEDIUMCVSS 5.4v13v142019-07-30
CVE-2019-10156 [MEDIUM] CWE-200 CVE-2019-10156: A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.1 A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any variable may be disclosed.
nvd
CVE-2017-18635P4MEDIUMCVSS 6.1v132019-09-25
CVE-2017-18635 [MEDIUM] CWE-79 CVE-2017-18635: An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could injec An XSS vulnerability was discovered in noVNC before 0.6.2 in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
nvd
CVE-2018-16876P4MEDIUMCVSS 5.3v142019-01-03
CVE-2018-16876 [MEDIUM] CWE-200 CVE-2018-16876: ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.
nvd
CVE-2013-6461P4MEDIUMCVSS 6.5v3.0v4.02019-11-05
CVE-2013-6461 [MEDIUM] CWE-776 CVE-2013-6461: Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
nvd
CVE-2020-10756P4MEDIUMCVSS 6.5v132020-07-09
CVE-2020-10756 [MEDIUM] CWE-125 CVE-2020-10756: An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emu An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible information disclosure. This fl
nvd
CVE-2014-9493P4MEDIUMCVSS 5.5v4.0v5.02015-01-07
CVE-2014-9493 [MEDIUM] CWE-264 CVE-2014-9493: The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 al The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
nvd
CVE-2013-6460P4MEDIUMCVSS 6.5v3.0v4.02019-11-05
CVE-2013-6460 [MEDIUM] CWE-776 CVE-2013-6460: Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
nvd
CVE-2018-1000808P4MEDIUMCVSS 5.9v132018-10-08
CVE-2018-1000808 [MEDIUM] CWE-404 CVE-2018-1000808: Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Rel Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploitable via Depends upon calling application, however it could be as s
nvd
CVE-2019-14905P4MEDIUMCVSS 5.6v132020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2020-10685P4MEDIUMCVSS 5.5v10v13+1 more2020-05-11
CVE-2020-10685 [MEDIUM] CWE-459 CVE-2020-10685: A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x b A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary dir
nvd
CVE-2015-0271P4MEDIUMCVSS 4.0v5.0v6.02015-03-10
CVE-2015-0271 [MEDIUM] CWE-200 CVE-2015-0271: The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (h The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
nvd
CVE-2015-5295P4MEDIUMCVSS 5.4v7.02016-01-20
CVE-2015-5295 [MEDIUM] CWE-119 CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
nvd
Redhat Openstack vulnerabilities | cvebase