Red Hat / Openstack Platform
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-1932 | Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss | MEDIUM | 5.3 | Nov 7, 2024 |
| CVE-2024-8007 | Openstack-tripleo-common: rhosp director disables tls verification for registry mirrors | HIGH | 8.1 | Aug 21, 2024 |
| CVE-2024-7319 | Openstack-heat: incomplete fix for cve-2023-1625 | MEDIUM | 5.3 | Aug 2, 2024 |
| CVE-2023-6725 | Tripleo-ansible: bind keys are world readable | MEDIUM | 5.5 | Mar 15, 2024 |
| CVE-2023-48795 | ssh: Prefix truncation attack on Binary Packet Protocol (BPP) | MEDIUM | 5.9 | Dec 18, 2023 |
| CVE-2023-5625 | Python-eventlet: patch regression for cve-2021-21419 in some red hat builds | HIGH | 7.5 | Nov 1, 2023 |
| CVE-2023-44487 KEV | HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) | MEDIUM | 6.9 | Oct 10, 2023 |
| CVE-2023-1633 | Insecure barbican configuration file leaking credential | MEDIUM | 6.6 | Sep 24, 2023 |
| CVE-2023-1636 | Incomplete container isolation | MEDIUM | 6.0 | Sep 24, 2023 |
| CVE-2023-1625 | Information leak in api | HIGH | 7.4 | Sep 24, 2023 |
| CVE-2022-3596 | Instack-undercloud: rsync leaks information to undercloud | HIGH | 7.5 | Sep 20, 2023 |
| CVE-2022-3261 | Plain-text passwords saved in /var/log/messages | HIGH | 7.5 | Sep 15, 2023 |
| CVE-2023-1108 | Undertow: infinite loop in sslconduit during close | HIGH | 7.5 | Sep 14, 2023 |
| CVE-2023-3637 | Openstack-neutron: unrestricted creation of security groups (fix for cve-2022-3277) | MEDIUM | 6.5 | Jul 25, 2023 |
| CVE-2023-3354 | Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service | HIGH | 7.5 | Jul 11, 2023 |
| CVE-2023-1668 | openvswitch: ip proto 0 triggers incorrect handling | HIGH | 8.2 | Apr 10, 2023 |
| CVE-2022-3277 | openstack-neutron: unrestricted creation of security groups | MEDIUM | 6.5 | Mar 6, 2023 |
| CVE-2022-3100 | openstack-barbican: access policy bypass via query string injection | HIGH | 7.1 | Jan 18, 2023 |
| CVE-2022-23451 | openstack-barbican: Barbican allows authenticated users to add/modify/delete arbitrary metadata on any secret | HIGH | 8.1 | Sep 6, 2022 |
| CVE-2022-23452 | openstack-barbican: Barbican allows anyone with an admin role to add their secrets to a different project's containers | MEDIUM | 4.9 | Sep 1, 2022 |
| CVE-2022-2447 | Openstack: Application credential token remains valid longer than expected | MEDIUM | 6.6 | Sep 1, 2022 |
| CVE-2022-2132 | dpdk: DoS when a Vhost header crosses more than two descriptors and exhausts all mbufs | HIGH | 8.6 | Aug 31, 2022 |
| CVE-2022-0718 | python-oslo-utils: incorrect password masking in debug output | MEDIUM | 6.9 | Aug 29, 2022 |
| CVE-2021-3563 | Keystone: Verification of application credentials is silently length-limited | CRITICAL | 9.1 | Aug 26, 2022 |
| CVE-2021-3979 | ceph: Ceph volume does not honour osd_dmcrypt_key_size | MEDIUM | 6.5 | Aug 25, 2022 |
Showing 1 to 25 of 39 CVEs