Redhat

Openstack

212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 16.03.2020 16:15:14
  • Zuletzt bearbeitet 21.11.2024 05:11:17

A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp a...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 16.03.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.03.2020 16:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be ...

  • EPSS 0.04%
  • Veröffentlicht 12.03.2020 18:15:12
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 11.03.2020 19:15:13
  • Zuletzt bearbeitet 21.11.2024 05:11:16

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 19.02.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:46:40

Nokogiri before 1.5.4 is vulnerable to XXE attacks

  • EPSS 0.49%
  • Veröffentlicht 11.02.2020 20:15:11
  • Zuletzt bearbeitet 21.11.2024 05:11:13

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_s...

  • EPSS 1.75%
  • Veröffentlicht 08.02.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 02:33:45

The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fiel...

  • EPSS 2.25%
  • Veröffentlicht 31.01.2020 22:15:11
  • Zuletzt bearbeitet 21.11.2024 02:35:42

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecifie...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 02.01.2020 15:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:30

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper ve...