Skip to main content

Vendor/product archive

redhat / openstack CVEs

Beta · best-effort

212 CVEs tagged to redhat / openstack18 Critical, 63 High, 119 Medium, 12 Low, 0 Unrated.

CVE-2023-2088

Published May 12, 2023

A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exp…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4134

Published Mar 6, 2023

A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using t…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-38065

Published Dec 21, 2022

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-1655

Published Jul 22, 2022

An Incorrect Permission Assignment for Critical Resource flaw was found in Horizon on Red Hat OpenStack. Horizon session cookies are created without the HttpOnly flag despite Hori…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3620

Published Mar 3, 2022

A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user credentials is disclosed by default in the traceback error mes…

CVSS 5.5 · Medium

CVE-2021-3930

Published Feb 18, 2022

An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands in mode_sense_page() if the 'page' argument was set to MOD…

CVSS 6.5 · Medium

CVE-2021-31918

Published May 6, 2021

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threa…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14355

Published Oct 7, 2020

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk)…

CVSS 6.6 · Medium

CVE-2019-14900

Published Jul 6, 2020

A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals…

CVSS 6.5 · Medium

CVE-2020-10711

Published May 22, 2020

A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO…

CVSS 5.9 · Medium

CVE-2020-1758

Published May 15, 2020

A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an att…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 212 CVEsPage 1 of 9