Redhat

Openstack

212 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.12.2019 20:15:11
  • Zuletzt bearbeitet 21.11.2024 01:44:43

The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • EPSS 0.6%
  • Veröffentlicht 26.12.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:31:11

In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Spec...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 20.12.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:11

Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any pr...

  • EPSS 0.52%
  • Veröffentlicht 20.12.2019 23:15:11
  • Zuletzt bearbeitet 21.11.2024 04:31:11

Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-En...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 10.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:51:10

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

  • EPSS 0.83%
  • Veröffentlicht 10.12.2019 15:15:11
  • Zuletzt bearbeitet 21.11.2024 01:51:10

python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

  • EPSS 0.28%
  • Veröffentlicht 10.12.2019 14:15:10
  • Zuletzt bearbeitet 21.11.2024 01:50:23

openstack-utils openstack-db has insecure password creation

  • EPSS 0.37%
  • Veröffentlicht 26.11.2019 14:15:11
  • Zuletzt bearbeitet 21.11.2024 04:27:30

ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None

Exploit
  • EPSS 0.79%
  • Veröffentlicht 23.11.2019 00:15:10
  • Zuletzt bearbeitet 02.04.2025 14:13:43

Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of servi...

  • EPSS 0.48%
  • Veröffentlicht 22.11.2019 23:15:11
  • Zuletzt bearbeitet 02.04.2025 14:13:43

Pivotal RabbitMQ, 3.7 versions prior to v3.7.20 and 3.8 version prior to v3.8.1, and RabbitMQ for PCF, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain two endpoints, federation and shovel, which do not properly sanitize u...