Home/Product/redhat openstack platform
Product

redhat openstack platform

39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-1932
all versions
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtm
6.1MEDIUM
CVE-2024-8007
all versions
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability
8.1HIGH
CVE-2024-7319
all versions
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenS
5.0MEDIUM
CVE-2023-6725
all versions
An access-control flaw was found in the OpenStack Designate component where private configuration information including access key
5.5MEDIUM
CVE-2023-48795
all versions
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9MEDIUM
CVE-2023-5625
all versions
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting i
5.3MEDIUM
CVE-2023-44487
all versions
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5HIGH
CVE-2023-1636
all versions
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an a
6.0MEDIUM
CVE-2023-1633
all versions
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration
6.6MEDIUM
CVE-2023-1625
all versions
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack sh
7.4HIGH
CVE-2022-3596
all versions
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive d
7.5HIGH
CVE-2022-3261
all versions
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud u
4.4MEDIUM
CVE-2023-1108
all versions
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status update
7.5HIGH
CVE-2023-3637
all versions
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a
4.3MEDIUM
CVE-2023-3354
all versions
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number
7.5HIGH
CVE-2023-1668
all versions
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without th
8.2HIGH
CVE-2022-3277
all versions
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a
6.5MEDIUM
CVE-2022-3100
all versions
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing
5.9MEDIUM
CVE-2022-23451
all versions
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authentica
8.1HIGH
CVE-2022-2447
all versions
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a
6.6MEDIUM
CVE-2022-23452
all versions
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project co
4.9MEDIUM
CVE-2022-2132
all versions
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service trigg
8.6HIGH
CVE-2022-0718
all versions
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect maskin
4.9MEDIUM
CVE-2021-3563
all versions
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypa
7.4HIGH
CVE-2021-3979
all versions
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in
6.5MEDIUM
CVE-2020-14394
all versions
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Bl
3.2LOW
CVE-2022-0866
all versions
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that i
5.3MEDIUM
CVE-2021-20257
all versions
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descripto
6.5MEDIUM
CVE-2021-3654
all versions
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect t
6.1MEDIUM
CVE-2020-1690
all versions
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a
6.5MEDIUM
CVE-2019-12067
all versions
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the comma
6.5MEDIUM
CVE-2021-20267
all versions
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in contr
7.1HIGH
CVE-2021-20270
all versions
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting o
7.5HIGH
CVE-2020-27781
all versions
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege es
7.1HIGH
CVE-2020-25658
all versions
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption
7.5HIGH
CVE-2020-25743
all versions
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma
3.2LOW
CVE-2020-14365
all versions
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when install
7.1HIGH
CVE-2020-10731
all versions
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabl
9.9CRITICAL
CVE-2017-15114
all versions
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin