CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Openstack Redhat2Barbican Openstack PlatformJun 17, 2026 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and ca...Show more |
4Debian DpdkFedoraproject+1 more8Data Plane Development Kit Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Aug 31, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. |
3Debian OpenstackRedhat4Debian Linux Openshift Container PlatformOpenstack Platform+1 moreJun 17, 2026 Aug 29, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstack PlatformJun 17, 2026 Aug 26, 2022 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat fr...Show more |
2Fedoraproject Redhat7Ceph Storage Ceph Storage For Ibm Z SystemsCeph Storage For Power+4 moreJun 17, 2026 Aug 25, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited...Show more |
3Fedoraproject QemuRedhat5Enterprise Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Aug 17, 2022 N/A· v4 3.2 LOW· v3 N/A· v2 An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the h...Show more |
1Redhat 3Jboss Enterprise Application Platform Openstack PlatformWildflyJun 17, 2026 May 10, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBCom...Show more |
4Debian FedoraprojectQemu+1 more8Codeready Linux Builder Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Mar 16, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. Th...Show more |
2Openstack Redhat2Nova Openstack PlatformJun 17, 2026 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. |
1Redhat 2Openstack Selinux Openstack PlatformJun 17, 2026 Jun 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack...Show more |
4Debian FedoraprojectQemu+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jun 2, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null. |
2Openstack Redhat2Neutron Openstack PlatformJun 17, 2026 May 28, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses...Show more |
4Debian FedoraprojectPygments+1 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "except...Show more |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
3Fedoraproject Python Rsa ProjectRedhat3Fedora Openstack PlatformPython RsaJun 17, 2026 Nov 12, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that python-rsa is vulnerable to Bleichenbacher timing attacks. An attacker can use this flaw via the RSA decryption API to decrypt parts of the cipher text encrypted with RSA. |
2Qemu Redhat3Enterprise Linux Openstack PlatformQemuJun 17, 2026 Oct 6, 2020 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 hw/ide/pci.c in QEMU before 5.1.1 can trigger a NULL pointer dereference because it lacks a pointer check before an ide_cancel_dma_sync call. |
2Debian Redhat5Ansible Engine Ansible TowerCeph Storage+2 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even whe...Show more |
1Redhat 1Openstack Platform Jun 17, 2026 Jul 31, 2020 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux enabled. This flaw causes sVirt, an important isolation mechanism, to be disabled for all runni...Show more |
When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this...Show more |