Redhat

Openstack

212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.5%
  • Veröffentlicht 14.12.2013 17:21:46
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from ...

  • EPSS 0.03%
  • Veröffentlicht 23.11.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.

  • EPSS 0.05%
  • Veröffentlicht 23.11.2013 17:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

rss-newsfeed.php in Nagios Core 3.4.4, 3.5.1, and earlier, when MAGPIE_CACHE_ON is set to 1, allows local users to overwrite arbitrary files via a symlink attack on /tmp/magpie_cache.

  • EPSS 0.52%
  • Veröffentlicht 20.11.2013 14:12:21
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple SQL injection vulnerabilities in app/models/concerns/host_common.rb in Foreman before 1.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) fqdn or (2) hostgroup parameter.

Exploit
  • EPSS 0.37%
  • Veröffentlicht 29.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (n...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 29.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), ...

  • EPSS 0.58%
  • Veröffentlicht 30.09.2013 22:55:04
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.

  • EPSS 0.94%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.

  • EPSS 0.7%
  • Veröffentlicht 16.09.2013 19:14:38
  • Zuletzt bearbeitet 11.04.2025 00:51:21

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

  • EPSS 47.45%
  • Veröffentlicht 31.07.2013 13:20:25
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role...