Redhat

Openstack

214 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.08%
  • Veröffentlicht 19.09.2018 16:29:01
  • Zuletzt bearbeitet 21.11.2024 03:54:05

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The decode_bundle function inside lib/ofp-actions.c is affected by a buffer over-read issue during BUNDLE action decoding.

  • EPSS 1.13%
  • Veröffentlicht 19.09.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:54:05

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The O...

  • EPSS 0.13%
  • Veröffentlicht 10.09.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:26

The OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could potentially allow an attacker to serve malicious code to the image builder and install in the resultant containe...

  • EPSS 0.4%
  • Veröffentlicht 10.09.2018 19:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:28

When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existin...

  • EPSS 0.24%
  • Veröffentlicht 27.08.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:14:08

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero p...

  • EPSS 0.07%
  • Veröffentlicht 22.08.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:23:51

A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several lines for the mistral user that...

  • EPSS 1.56%
  • Veröffentlicht 09.08.2018 20:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:17

A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untru...

  • EPSS 1.2%
  • Veröffentlicht 31.07.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:49:02

In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects th...

  • EPSS 0.18%
  • Veröffentlicht 30.07.2018 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:15

A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.

  • EPSS 0.4%
  • Veröffentlicht 30.07.2018 16:29:00
  • Zuletzt bearbeitet 21.11.2024 03:42:16

A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an...