Redhat

Openstack Platform

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 07.11.2024 10:15:04
  • Zuletzt bearbeitet 24.06.2025 13:07:42

A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an inva...

  • EPSS 0.23%
  • Veröffentlicht 21.08.2024 14:15:09
  • Zuletzt bearbeitet 25.11.2024 05:15:12

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS certificate verification for reg...

  • EPSS 0.37%
  • Veröffentlicht 02.08.2024 21:16:31
  • Zuletzt bearbeitet 07.10.2024 19:15:11

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

  • EPSS 0.08%
  • Veröffentlicht 08.05.2024 09:15:09
  • Zuletzt bearbeitet 21.11.2024 09:42:49

The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided...

  • EPSS 0.04%
  • Veröffentlicht 15.03.2024 13:15:06
  • Zuletzt bearbeitet 30.07.2025 20:21:05

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw...

Medienbericht Exploit
  • EPSS 64.06%
  • Veröffentlicht 18.12.2023 16:15:10
  • Zuletzt bearbeitet 29.09.2025 21:56:10

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...

  • EPSS 0.08%
  • Veröffentlicht 01.11.2023 14:15:38
  • Zuletzt bearbeitet 06.12.2024 11:15:07

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products.

Warnung Medienbericht Exploit
  • EPSS 94.44%
  • Veröffentlicht 10.10.2023 14:15:10
  • Zuletzt bearbeitet 11.06.2025 17:29:54

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

  • EPSS 0.02%
  • Veröffentlicht 24.09.2023 01:15:43
  • Zuletzt bearbeitet 21.11.2024 07:39:35

A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.

Exploit
  • EPSS 0.12%
  • Veröffentlicht 24.09.2023 01:15:43
  • Zuletzt bearbeitet 21.11.2024 07:39:34

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, inte...