CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jul 6, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A insecure configuration for certificate verification (http.verify_mode = OpenSSL::SSL::VERIFY_NONE) may lead to verification bypass in Red Hat CloudForms 5.x. |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 9.1 CRITICAL· v3 6.5 MEDIUM· v2 A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS command injection vulnerability can be exploited by authenticated attacker while setuping conversio...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 was vulnerable to Server-Side Request Forgery (SSRF) flaw. With the access to add Ansible Tower provider, an attacker could scan and attack systems from the internal network which are not nor...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Aug 11, 2020 N/A· v4 6.3 MEDIUM· v3 4.9 MEDIUM· v2 Red Hat CloudForms 4.7 and 5 is affected by CSV Injection flaw, a crafted payload stays dormant till a victim export as CSV and opens the file with Excel. Once the victim opens the file, the formula executes, triggering...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jun 22, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console...Show more |
3Fedoraproject OpensuseRedhat8Ansible Engine Ansible TowerBackports Sle+5 moreNov 21, 2024 Mar 31, 2020 N/A· v4 5.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreNov 21, 2024 Mar 16, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a...Show more |
1Redhat 4Ansible Ansible TowerCloudforms Management Engine+1 moreNov 21, 2024 Mar 16, 2020 N/A· v4 3.9 LOW· v3 2.6 LOW· v2 A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacke...Show more |
2Fedoraproject Redhat5Ansible Ansible TowerCloudforms Management Engine+2 moreNov 21, 2024 Mar 16, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the f...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreNov 21, 2024 Mar 16, 2020 N/A· v4 4.6 MEDIUM· v3 3.6 LOW· v2 A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreNov 21, 2024 Mar 12, 2020 N/A· v4 3.9 LOW· v3 3.3 LOW· v2 A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the s...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreNov 21, 2024 Mar 11, 2020 N/A· v4 5.0 MEDIUM· v3 3.7 LOW· v2 A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temp...Show more |
2Nokogiri Redhat8Cloudforms Management Engine Enterprise MrgNokogiri+5 moreNov 21, 2024 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri before 1.5.4 is vulnerable to XXE attacks |
3Debian OpensuseRedhat8Ansible Ansible TowerBackports Sle+5 moreNov 21, 2024 Jan 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results e...Show more |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration |
1Redhat 2Cloudforms Cloudforms Management EngineNov 21, 2024 Dec 13, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 CFME: CSRF protection vulnerability via permissive check of the referrer header |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Nov 22, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripting due to improper sa...Show more |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits |
3Debian NokogiriRedhat7Cloudforms Management Engine Debian LinuxEnterprise Mrg+4 moreNov 21, 2024 Nov 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents |
1Redhat 1Cloudforms Management Engine Nov 21, 2024 Jun 27, 2019 N/A· v4 6.5 MEDIUM· v3 6.0 MEDIUM· v2 A stored cross-site scripting (XSS) vulnerability was found in the PDF export component of CloudForms, versions 5.9 and 5.10, due to user input is not properly sanitized. An attacker with least privilege to edit compute...Show more |