CVE-2020-10685
- EPSS 0.14%
- Published 11.05.2020 14:15:11
- Last modified 21.11.2024 04:55:51
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts...
CVE-2020-12458
- EPSS 0.05%
- Published 29.04.2020 16:15:11
- Last modified 21.11.2024 04:59:44
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encr...
CVE-2020-1760
- EPSS 0.29%
- Published 23.04.2020 15:15:14
- Last modified 21.11.2024 05:11:19
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
CVE-2020-1699
- EPSS 1.82%
- Published 21.04.2020 17:15:12
- Last modified 21.11.2024 05:11:11
A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information di...
CVE-2020-1759
- EPSS 0.41%
- Published 13.04.2020 13:15:13
- Last modified 21.11.2024 05:11:19
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and pote...
CVE-2020-1712
- EPSS 0.11%
- Published 31.03.2020 17:15:26
- Last modified 21.11.2024 05:11:13
A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially...
CVE-2019-14905
- EPSS 0.05%
- Published 31.03.2020 17:15:26
- Last modified 21.11.2024 04:27:39
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code c...
CVE-2019-14864
- EPSS 0.94%
- Published 02.01.2020 15:15:12
- Last modified 21.11.2024 04:27:31
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This woul...
CVE-2019-14859
- EPSS 0.07%
- Published 02.01.2020 15:15:11
- Last modified 21.11.2024 04:27:30
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper ve...
CVE-2019-19337
- EPSS 0.55%
- Published 23.12.2019 17:15:11
- Last modified 21.11.2024 04:34:36
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length he...