Redhat

Openstack

214 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Published 26.03.2019 18:29:00
  • Last modified 21.11.2024 03:53:27

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as pr...

  • EPSS 0.12%
  • Published 26.03.2019 18:29:00
  • Last modified 21.11.2024 04:42:38

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

Exploit
  • EPSS 2%
  • Published 13.03.2019 02:29:00
  • Last modified 21.11.2024 04:52:12

An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't supp...

  • EPSS 1.03%
  • Published 03.01.2019 15:29:01
  • Last modified 21.11.2024 03:53:30

ansible before versions 2.5.14, 2.6.11, 2.7.5 is vulnerable to a information disclosure flaw in vvv+ mode with no_log on that can lead to leakage of sensible data.

  • EPSS 0.07%
  • Published 31.10.2018 13:29:00
  • Last modified 21.11.2024 02:47:52

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system informatio...

  • EPSS 0.12%
  • Published 19.10.2018 22:29:02
  • Last modified 21.11.2024 03:55:56

Qemu has integer overflows because IOReadHandler and its associated functions use a signed integer data type for a size value.

  • EPSS 2.08%
  • Published 09.10.2018 22:29:01
  • Last modified 21.11.2024 03:55:17

qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.

  • EPSS 4.51%
  • Published 08.10.2018 15:29:00
  • Last modified 21.11.2024 03:40:23

Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This...

  • EPSS 0.16%
  • Published 08.10.2018 15:29:00
  • Last modified 21.11.2024 03:40:23

Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. Th...

Exploit
  • EPSS 0.77%
  • Published 19.09.2018 16:29:01
  • Last modified 21.11.2024 03:54:05

An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit, flows that are added in a bundle are applied to ofproto in order. If a flow cannot be added (e.g., the flow...