Redhat Openstack vulnerabilities
208 known vulnerabilities affecting redhat/openstack.
Total CVEs
208
CISA KEV
0
Public exploits
9
Exploited in wild
4
Severity breakdown
CRITICAL23HIGH63MEDIUM111LOW11
Vulnerabilities
Page 8 of 11
CVE-2018-10892P4MEDIUMCVSS 5.3v122018-07-06
CVE-2018-10892 [MEDIUM] CWE-250 CVE-2018-10892: The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not b
The default OCI linux spec in oci/defaults{_linux}.go in Docker/Moby from 1.11 to current does not block /proc/acpi pathnames. The flaw allows an attacker to modify host's hardware like enabling/disabling bluetooth or turning up/down keyboard brightness.
nvd
CVE-2016-4020P4MEDIUMCVSS 6.5v6.0v7.0+4 more2016-05-25
CVE-2016-4020 [MEDIUM] CVE-2016-4020: The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable,
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
nvd
CVE-2018-1059P4MEDIUMCVSS 6.1v8v9+3 more2018-04-24
CVE-2018-1059 [MEDIUM] CWE-200 CVE-2018-1059: The DPDK vhost-user interface does not check to verify that all the requested guest physical range i
The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
nvd
CVE-2013-2255P4MEDIUMCVSS 5.9v3.0v4.02019-11-01
CVE-2013-2255 [MEDIUM] CWE-295 CVE-2013-2255: HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
nvd
CVE-2021-3930P4MEDIUMCVSS 6.5v10v132022-02-18
CVE-2021-3930 [MEDIUM] CWE-193 CVE-2021-3930: An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing
An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MODE_PAGE_ALLS (0x3f). A malicious guest could use this flaw to potentially crash QEMU, resulting in a denial of service condition.
nvd
CVE-2016-4428P4MEDIUMCVSS 5.4v6.0v7.0+2 more2016-07-12
CVE-2016-4428 [MEDIUM] CWE-79 CVE-2016-4428: Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
nvd
CVE-2017-3641P4MEDIUMCVSS 4.9v122017-08-08
CVE-2017-3641 [MEDIUM] CVE-2017-3641: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2014-4615P4MEDIUMCVSS 5.0v4.02014-08-19
CVE-2014-4615 [MEDIUM] CWE-200 CVE-2014-4615: The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
nvd
CVE-2022-3101P4MEDIUMCVSS 5.5v16.1v16.22023-03-23
CVE-2022-3101 [MEDIUM] CWE-22 CVE-2022-3101: A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deploymen
nvd
CVE-2022-3146P4MEDIUMCVSS 5.5v16.1v16.22023-03-23
CVE-2022-3146 [MEDIUM] CWE-22 CVE-2022-3146: A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack
nvd
CVE-2017-3636P4MEDIUMCVSS 5.3v122017-08-08
CVE-2017-3636 [MEDIUM] CVE-2017-3636: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Support
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vuln
nvd
CVE-2016-9911P4MEDIUMCVSS 6.5v6.0v7.0+4 more2016-12-23
CVE-2016-9911 [MEDIUM] CWE-772 CVE-2016-9911: Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage is
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
nvd
CVE-2018-2781P4MEDIUMCVSS 4.9v122018-04-19
CVE-2018-2781 [MEDIUM] CVE-2018-2781: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulne
nvd
CVE-2017-2621P4MEDIUMCVSS 5.5v9v102018-07-27
CVE-2017-2621 [MEDIUM] CWE-552 CVE-2017-2621: An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 a
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
nvd
CVE-2021-3620P4MEDIUMCVSS 5.5v1v16.12022-03-03
CVE-2021-3620 [MEDIUM] CWE-209 CVE-2021-3620: A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as
A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error message. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2017-2622P4MEDIUMCVSS 5.5v102018-07-27
CVE-2017-2622 [MEDIUM] CWE-552 CVE-2017-2622: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log dire
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
nvd
CVE-2018-2813P4MEDIUMCVSS 4.3v122018-04-19
CVE-2018-2813 [MEDIUM] CVE-2018-2813: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported v
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2017-3651P4MEDIUMCVSS 4.3v122017-08-08
CVE-2017-3651 [MEDIUM] CVE-2017-3651: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Suppor
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this v
nvd
CVE-2016-9907P4MEDIUMCVSS 6.5v6.0v7.0+4 more2016-12-23
CVE-2016-9907 [MEDIUM] CWE-772 CVE-2016-9907: Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leak
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
nvd
CVE-2016-9921P4MEDIUMCVSS 6.5v6.0v7.0+4 more2016-12-23
CVE-2016-9921 [MEDIUM] CWE-369 CVE-2016-9921: Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
nvd