Redhat

Openstack Platform

40 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.1%
  • Published 07.06.2021 20:15:07
  • Last modified 21.11.2024 05:11:10

An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send...

  • EPSS 0.14%
  • Published 02.06.2021 15:15:07
  • Last modified 21.11.2024 04:22:10

The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

  • EPSS 0.12%
  • Published 28.05.2021 19:15:07
  • Last modified 21.11.2024 05:46:14

A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses of other systems on the netwo...

  • EPSS 0.12%
  • Published 23.03.2021 17:15:13
  • Last modified 21.11.2024 05:46:15

An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.

  • EPSS 0.04%
  • Published 18.12.2020 21:15:12
  • Last modified 21.11.2024 05:21:49

User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. ...

Exploit
  • EPSS 0.23%
  • Published 12.11.2020 14:15:22
  • Last modified 21.11.2024 05:18:22

It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA.

  • EPSS 0.04%
  • Published 06.10.2020 15:15:15
  • Last modified 21.11.2024 05:18:38

hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call.

  • EPSS 0.07%
  • Published 23.09.2020 13:15:15
  • Last modified 21.11.2024 05:03:06

A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to ...

  • EPSS 0.28%
  • Published 31.07.2020 13:15:12
  • Last modified 21.11.2024 04:55:57

A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all running virtual machines.

  • EPSS 0.7%
  • Published 27.11.2017 16:29:00
  • Last modified 20.04.2025 01:37:25

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows these services to conn...