Redhat

Openstack

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 8.06%
  • Veröffentlicht 06.02.2014 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML docum...

  • EPSS 0.39%
  • Veröffentlicht 02.02.2014 00:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 14.12.2013 17:21:46
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from ...

  • EPSS 0.04%
  • Veröffentlicht 23.11.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

  • EPSS 0.06%
  • Veröffentlicht 23.11.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.

  • EPSS 0.35%
  • Veröffentlicht 20.11.2013 14:12:21
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 29.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (n...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 29.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), ...

  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 22:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

  • EPSS 0.54%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.