Redhat

Openstack

214 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.25%
  • Published 31.01.2020 22:15:11
  • Last modified 21.11.2024 02:35:42

The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecifie...

Exploit
  • EPSS 0.07%
  • Published 02.01.2020 15:15:11
  • Last modified 21.11.2024 04:27:30

A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper ve...

Exploit
  • EPSS 0.07%
  • Published 30.12.2019 20:15:11
  • Last modified 21.11.2024 01:44:43

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • EPSS 0.6%
  • Published 26.12.2019 17:15:13
  • Last modified 21.11.2024 04:31:11

In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Spec...

Exploit
  • EPSS 0.43%
  • Published 20.12.2019 23:15:11
  • Last modified 21.11.2024 04:31:11

Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any pr...

  • EPSS 0.52%
  • Published 20.12.2019 23:15:11
  • Last modified 21.11.2024 04:31:11

Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-En...

Exploit
  • EPSS 0.09%
  • Published 10.12.2019 15:15:11
  • Last modified 21.11.2024 01:51:10

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

  • EPSS 0.83%
  • Published 10.12.2019 15:15:11
  • Last modified 21.11.2024 01:51:10

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

  • EPSS 0.28%
  • Published 10.12.2019 14:15:10
  • Last modified 21.11.2024 01:50:23

openstack-utils openstack-db has insecure password creation

  • EPSS 0.37%
  • Published 26.11.2019 14:15:11
  • Last modified 21.11.2024 04:27:30

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None