CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Hibernate Redhat5Codeready Studio Hibernate ValidatorJboss Enterprise Application Platform+2 moreJun 17, 2026 Nov 7, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than characte...Show more |
A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS ce...Show more |
2Openstack Redhat2Heat Openstack PlatformJun 17, 2026 Aug 2, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix a...Show more |
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any con...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
1Redhat 5Openshift Container Platform For Arm64 Openshift Container Platform For LinuxoneOpenshift Container Platform For Power+2 moreJun 17, 2026 Nov 1, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products. |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespac...Show more |
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. |
2Openstack Redhat2Heat Openstack PlatformJun 17, 2026 Sep 24, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impac...Show more |
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising p...Show more |
A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreJun 17, 2026 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unco...Show more |
3Fedoraproject QemuRedhat4Enterprise Linux FedoraOpenstack Platform+1 moreJun 17, 2026 Jul 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection....Show more |
3Cloudbase DebianRedhat6Debian Linux Fast DatapathOpen Vswitch+3 moreJun 17, 2026 Apr 10, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapa...Show more |
2Openstack Redhat2Neutron Openstack PlatformJun 17, 2026 Mar 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unco...Show more |
2Openstack Redhat4Barbican OpenstackOpenstack For Ibm Power+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. |
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 6, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This...Show more |
2Openstack Redhat4Keystone Openstack PlatformQuay+1 moreJun 17, 2026 Sep 1, 2022 N/A· v4 6.6 MEDIUM· v3 N/A· v2 A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote admini...Show more |