threat
engine
.sh
Back
·
··:··
Home
/
Product
/
redhat openstack platform
Product
redhat openstack platform
39 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-1932
all versions
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtm
6.1
MEDIUM
CVE-2024-8007
all versions
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability
8.1
HIGH
CVE-2024-7319
all versions
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenS
5.0
MEDIUM
CVE-2023-6725
all versions
An access-control flaw was found in the OpenStack Designate component where private configuration information including access key
5.5
MEDIUM
CVE-2023-48795
all versions
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attacker
5.9
MEDIUM
CVE-2023-5625
all versions
A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting i
5.3
MEDIUM
CVE-2023-44487
all versions
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams q
7.5
HIGH
CVE-2023-1636
all versions
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an a
6.0
MEDIUM
CVE-2023-1633
all versions
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration
6.6
MEDIUM
CVE-2023-1625
all versions
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack sh
7.4
HIGH
CVE-2022-3596
all versions
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive d
7.5
HIGH
CVE-2022-3261
all versions
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud u
4.4
MEDIUM
CVE-2023-1108
all versions
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status update
7.5
HIGH
CVE-2023-3637
all versions
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a
4.3
MEDIUM
CVE-2023-3354
all versions
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number
7.5
HIGH
CVE-2023-1668
all versions
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without th
8.2
HIGH
CVE-2022-3277
all versions
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a
6.5
MEDIUM
CVE-2022-3100
all versions
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing
5.9
MEDIUM
CVE-2022-23451
all versions
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authentica
8.1
HIGH
CVE-2022-2447
all versions
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a
6.6
MEDIUM
CVE-2022-23452
all versions
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project co
4.9
MEDIUM
CVE-2022-2132
all versions
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service trigg
8.6
HIGH
CVE-2022-0718
all versions
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect maskin
4.9
MEDIUM
CVE-2021-3563
all versions
A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypa
7.4
HIGH
CVE-2021-3979
all versions
A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in
6.5
MEDIUM
CVE-2020-14394
all versions
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Bl
3.2
LOW
CVE-2022-0866
all versions
This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that i
5.3
MEDIUM
CVE-2021-20257
all versions
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descripto
6.5
MEDIUM
CVE-2021-3654
all versions
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect t
6.1
MEDIUM
CVE-2020-1690
all versions
An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a
6.5
MEDIUM
CVE-2019-12067
all versions
The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the comma
6.5
MEDIUM
CVE-2021-20267
all versions
A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in contr
7.1
HIGH
CVE-2021-20270
all versions
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting o
7.5
HIGH
CVE-2020-27781
all versions
User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege es
7.1
HIGH
CVE-2020-25658
all versions
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption
7.5
HIGH
CVE-2020-25743
all versions
hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma
3.2
LOW
CVE-2020-14365
all versions
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when install
7.1
HIGH
CVE-2020-10731
all versions
A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabl
9.9
CRITICAL
CVE-2017-15114
all versions
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate
8.1
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin