Skip to main content

Vendor/product archive

redhat / openstack_platform CVEs

Beta · best-effort

37 CVEs tagged to redhat / openstack_platform1 Critical, 15 High, 19 Medium, 2 Low, 0 Unrated.

CVE-2024-8007

Published Aug 21, 2024

A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7319

Published Aug 2, 2024

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden featur…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-6725

Published Mar 15, 2024

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5625

Published Nov 1, 2023

A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied fo…

CVSS 5.3 · Medium

CVE-2023-1625

Published Sep 24, 2023

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are suppos…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3596

Published Sep 20, 2023

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the under…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3261

Published Sep 15, 2023

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive i…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3637

Published Jul 25, 2023

An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. T…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3979

Published Aug 25, 2022

A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random k…

CVSS 6.5 · Medium
Showing 1-25 of 37 CVEsPage 1 of 2