Redhat

Cloudforms Management Engine

42 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 12.03.2020 18:15:12
  • Last modified 21.11.2024 05:11:16

A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could ta...

Exploit
  • EPSS 0.04%
  • Published 11.03.2020 19:15:13
  • Last modified 21.11.2024 05:11:16

A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in ...

Exploit
  • EPSS 0.32%
  • Published 19.02.2020 15:15:11
  • Last modified 21.11.2024 01:46:40

Nokogiri before 1.5.4 is vulnerable to XXE attacks

Exploit
  • EPSS 0.94%
  • Published 02.01.2020 15:15:12
  • Last modified 21.11.2024 04:27:31

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...

  • EPSS 0.1%
  • Published 15.12.2019 22:15:11
  • Last modified 21.11.2024 02:08:19

CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

  • EPSS 0.36%
  • Published 13.12.2019 13:15:10
  • Last modified 21.11.2024 02:01:37

CFME: CSRF protection vulnerability via permissive check of the referrer header

  • EPSS 0.26%
  • Published 22.11.2019 12:15:11
  • Last modified 21.11.2024 03:42:08

cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sanitization of user input in Na...

Exploit
  • EPSS 2.05%
  • Published 05.11.2019 15:15:11
  • Last modified 21.11.2024 01:59:16

Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

Exploit
  • EPSS 2.52%
  • Published 05.11.2019 15:15:11
  • Last modified 21.11.2024 01:59:16

Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

  • EPSS 0.4%
  • Published 27.06.2019 21:15:10
  • Last modified 21.11.2024 04:18:35

A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute is able to execute a XSS attac...