Redhat

Openstack

214 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.02%
  • Published 24.03.2020 14:15:12
  • Last modified 21.11.2024 04:55:50

A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts...

  • EPSS 0.14%
  • Published 16.03.2020 16:15:14
  • Last modified 21.11.2024 05:11:16

A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file...

  • EPSS 0.04%
  • Published 16.03.2020 16:15:14
  • Last modified 21.11.2024 05:11:17

A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp a...

Exploit
  • EPSS 0.14%
  • Published 16.03.2020 16:15:13
  • Last modified 21.11.2024 05:11:16

A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believ...

Exploit
  • EPSS 0.04%
  • Published 16.03.2020 16:15:13
  • Last modified 21.11.2024 05:11:16

A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be ...

  • EPSS 0.04%
  • Published 12.03.2020 18:15:12
  • Last modified 21.11.2024 05:11:16

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...

Exploit
  • EPSS 0.04%
  • Published 11.03.2020 19:15:13
  • Last modified 21.11.2024 05:11:16

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...

Exploit
  • EPSS 0.32%
  • Published 19.02.2020 15:15:11
  • Last modified 21.11.2024 01:46:40

Nokogiri before 1.5.4 is vulnerable to XXE attacks

  • EPSS 0.65%
  • Published 11.02.2020 20:15:11
  • Last modified 21.11.2024 05:11:13

An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_s...

  • EPSS 1.75%
  • Published 08.02.2020 19:15:10
  • Last modified 21.11.2024 02:33:45

The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fiel...