cbcvebase.

Redhat Openstack Platform vulnerabilities

39 known vulnerabilities affecting redhat/openstack_platform.

Total CVEs
39
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH16MEDIUM20LOW2

Vulnerabilities

Page 1 of 2
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCv16.1v16.2+1 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2023-48795P1MEDIUMCVSS 5.9ExploitedPoCv16.1v16.2+1 more2023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2021-3654P3MEDIUMCVSS 6.1PoCv16.1v16.22022-03-02
CVE-2021-3654 [MEDIUM] CWE-601 CVE-2021-3654: A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noV A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
nvd
CVE-2020-10731P3CRITICALCVSS 9.9v15.0v16.0+1 more2020-07-31
CVE-2020-10731 [CRITICAL] CWE-284 CVE-2020-10731: A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.
nvd
CVE-2017-15114P3HIGHCVSS 8.1v12.02017-11-27
CVE-2017-15114 [HIGH] CWE-295 CVE-2017-15114: When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it def When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to connect to libvirtd (which is equivalent to root access). If a vulnerability exists in another service it c
nvd
CVE-2022-23451P3HIGHCVSS 8.1v13.0v16.1+1 more2022-09-06
CVE-2022-23451 [HIGH] CWE-863 CVE-2022-23451: An authorization flaw was found in openstack-barbican. The default policy rules for the secret metad An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resourc
nvd
CVE-2021-3563P3HIGHCVSS 7.4v10.0v13.0+2 more2022-08-26
CVE-2021-3563 [HIGH] CWE-863 CVE-2021-3563: A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are ve A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2022-3596P3HIGHCVSS 7.5v13.02023-09-20
CVE-2022-3596 [HIGH] CWE-402 CVE-2022-3596: An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote at An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.
nvd
CVE-2023-1668P3HIGHCVSS 8.2v16.1v16.2+1 more2023-04-10
CVE-2023-1668 [HIGH] CWE-670 CVE-2023-1668: A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will instal A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow, but with an incorrect action, possi
nvd
CVE-2022-2132P3HIGHCVSS 8.6v13.02022-08-31
CVE-2022-2132 [HIGH] CWE-791 CVE-2022-2132: A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to c A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
nvd
CVE-2024-8007P3HIGHCVSS 8.1v16.1v16.2+1 more2024-08-21
CVE-2024-8007 [HIGH] CWE-295 CVE-2024-8007: A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for registry mirrors, which could enable a man-in-the-middle (MITM) attack.
nvd
CVE-2023-3354P3HIGHCVSS 7.5v13.02023-07-11
CVE-2023-3354 [HIGH] CWE-476 CVE-2023-3354: A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU che A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL poi
nvd
CVE-2023-1108P3HIGHCVSS 7.5v13.02023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd
CVE-2020-27781P3HIGHCVSS 7.1v13.02020-12-18
CVE-2020-27781 [HIGH] CWE-522 CVE-2020-27781: User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resul User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all users of the requesting OpenStack proj
nvd
CVE-2021-20267P3HIGHCVSS 7.1v10.0v13.0+2 more2021-05-28
CVE-2021-20267 [HIGH] CWE-345 CVE-2021-20267: A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully cr A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the network, resulting in denial of service or in some cases possibly interception of traffic intended for other
nvd
CVE-2022-3261P3HIGHCVSS 7.5v16.22023-09-15
CVE-2022-3261 [HIGH] CWE-256 CVE-2022-3261: A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages du A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.
nvd
CVE-2021-20270P3HIGHCVSS 7.5v10.02021-03-23
CVE-2021-20270 [HIGH] CWE-835 CVE-2021-20270: An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when pe An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
nvd
CVE-2023-5625P3HIGHCVSS 7.5v17.12023-11-01
CVE-2023-5625 [HIGH] CVE-2023-5625: A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch app A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.
nvd
CVE-2021-3979P3MEDIUMCVSS 6.5v13.02022-08-25
CVE-2021-3979 [MEDIUM] CWE-327 CVE-2021-3979: A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key l A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited for loss of confidentiality and integrity on encrypted disks.
nvd
CVE-2023-3637P4MEDIUMCVSS 6.5v13.0v16.22023-07-25
CVE-2023-3637 [MEDIUM] CWE-400 CVE-2023-3637: An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of ser
nvd
Redhat Openstack Platform vulnerabilities | cvebase