VendorsRed Hatopenstack15
Vulnerabilities

Red Hat Open Stack 15

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2019-14859
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
Published 2020-01-02 · Modified
9.1EPSS 0.015
CVE-2019-16789
HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers
Published 2019-12-26 · Modified
8.2EPSS 0.026
CVE-2019-11287
RabbitMQ Web Management Plugin DoS via heap overflow
Published 2019-11-22 · Modified
7.5EPSS 0.044
CVE-2019-16785
HTTP Request Smuggling: LF vs CRLF handling in Waitress
Published 2019-12-20 · Modified
7.5EPSS 0.025
CVE-2019-16786
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
Published 2019-12-20 · Modified
7.5EPSS 0.024
CVE-2020-1759
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
Published 2020-04-13 · Modified
6.8EPSS 0.016
CVE-2020-10753
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. Ceph versions 3.x and 4.x are vulnerable to this issue.
Published 2020-06-26 · Modified
6.5EPSS 0.016
CVE-2019-3866
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
Published 2019-11-08 · Modified
5.9EPSS 0.003
CVE-2020-10685
A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or copy modules. The temporary directory is created in /tmp leaves the s ts unencrypted. On Operating Systems which /tmp is not a tmpfs but part of the root partition, the directory is only cleared on boot and the decryp emains when the host is switched off. The system will be vulnerable when the system is not running. So decrypted data must be cleared as soon as possible and the data which normally is encrypted ble.
Published 2020-05-11 · Modified
5.5EPSS 0.004
CVE-2019-11281
RabbitMQ XSS attack
Published 2019-10-16 · Modified
4.8EPSS 0.012
CVE-2019-11291
RabbitMQ XSS attack via federation and shovel endpoints
Published 2019-11-22 · Modified
4.8EPSS 0.008