Red Hat / OpenStack
210 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-2088 | openstack-cinder: silently access other user's volumes | CRITICAL | 9.1 | May 12, 2023 |
| CVE-2022-3146 | tripleo-ansible: /etc/openstack/clouds.yaml discoverable | HIGH | 7.3 | Mar 23, 2023 |
| CVE-2022-3101 | tripleo-ansible: /var/lib/mistral/overcloud discoverable | HIGH | 7.3 | Mar 23, 2023 |
| CVE-2022-4134 | openstack: glance & ceph conflict which allows image tampering | MEDIUM | 4.8 | Mar 6, 2023 |
| CVE-2022-3100 | openstack-barbican: access policy bypass via query string injection | HIGH | 7.1 | Jan 18, 2023 |
| CVE-2022-38065 | oslo-privsep: privilege escalation vulnerability | HIGH | 8.8 | Dec 21, 2022 |
| CVE-2022-1655 | OpenStack: Horizon session cookies are not flagged HttpOnly | MEDIUM | 6.5 | Jul 22, 2022 |
| CVE-2021-4180 | openstack-tripleo-heat-templates: data leak of internal URL through keystone_authtoken | MEDIUM | 4.3 | Mar 23, 2022 |
| CVE-2021-3656 | kernel: SVM nested virtualization issue in KVM (VMLOAD/VMSAVE) | HIGH | 8.8 | Mar 4, 2022 |
| CVE-2021-3620 | Ansible: ansible-connection module discloses sensitive info in traceback error message | MEDIUM | 6.8 | Mar 3, 2022 |
| CVE-2021-3930 | QEMU: off-by-one error in mode_sense_page() in hw/scsi/scsi-disk.c | MEDIUM | 6.5 | Feb 18, 2022 |
| CVE-2020-25717 | samba: Active Directory (AD) domain user could become root on domain members | HIGH | 8.1 | Feb 18, 2022 |
| CVE-2016-2124 | samba: SMB1 client connections can be downgraded to plaintext authentication | MEDIUM | 6.8 | Feb 18, 2022 |
| CVE-2021-31918 | tripleo-ansible: ansible.log file is visible to unprivileged users | HIGH | 7.5 | May 6, 2021 |
| CVE-2020-27827 | lldp/openvswitch: denial of service via externally triggered memory leak | HIGH | 7.5 | Mar 18, 2021 |
| CVE-2020-14355 | spice: multiple buffer overflow vulnerabilities in QUIC decoding code | MEDIUM | 6.6 | Oct 7, 2020 |
| CVE-2020-14364 | QEMU: usb: out-of-bounds r/w access issue while processing usb packets | MEDIUM | 5.0 | Aug 31, 2020 |
| CVE-2020-9490 | httpd: Push diary crash on specifically crafted HTTP/2 header | HIGH | 7.5 | Aug 7, 2020 |
| CVE-2020-10756 | QEMU: slirp: networking out-of-bounds read information disclosure vulnerability | MEDIUM | 6.5 | Jul 9, 2020 |
| CVE-2019-14900 | hibernate: SQL injection issue in Hibernate ORM | MEDIUM | 6.5 | Jul 6, 2020 |
| CVE-2020-10753 | ceph: radosgw: HTTP header injection via CORS ExposeHeader tag | MEDIUM | 6.5 | Jun 26, 2020 |
| CVE-2020-10711 | Kernel: NetLabel: null pointer dereference while receiving CIPSO packet with null category may cause kernel panic | MEDIUM | 5.9 | May 22, 2020 |
| CVE-2020-1758 | keycloak: improper verification of certificate with host mismatch could result in information disclosure | MEDIUM | 5.9 | May 15, 2020 |
| CVE-2020-10685 | Ansible: modules which use files encrypted with vault are not properly cleaned up | MEDIUM | 6.8 | May 11, 2020 |
| CVE-2020-1759 | ceph: secure mode of msgr2 breaks both confidentiality and integrity aspects for long-lived sessions | MEDIUM | 6.8 | Apr 13, 2020 |
Showing 1 to 25 of 210 CVEs