Redhat
Redhat Openstack Platform: vulnerabilidades y CVE
Redhat Openstack Platform tiene 43 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE43
Últimos 12 meses0
Críticas1
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-1932 | Media (6.1) | 0.46% | — | 7 nov 2024 | A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than… |
| CVE-2024-8007 | Alta (8.1) | 0.39% | — | 21 ago 2024 | A flaw was found in the openstack-tripleo-common component of the Red Hat OpenStack Platform (RHOSP) director. This vulnerability allows an attacker to deploy potentially compromised container images via disabling TLS… |
| CVE-2024-7319 | Media (5) | 0.39% | — | 2 ago 2024 | An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix… |
| CVE-2024-4840 | Media (5.5) | 0.20% | — | 14 may 2024 | An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to… |
| CVE-2024-4438 | Alta (7.5) | 0.79% | — | 8 may 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack… |
| CVE-2024-4437 | Alta (7.5) | 0.77% | — | 8 may 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2021-44716. This issue occurs because the etcd package in the Red Hat OpenStack platform is using… |
| CVE-2024-4436 | Alta (7.5) | 0.77% | — | 8 may 2024 | The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2022-41723. This issue occurs because the etcd package in the Red Hat OpenStack platform is using… |
| CVE-2023-6725 | Media (5.5) | 0.20% | — | 15 mar 2024 | An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any… |
| CVE-2023-48795 | Media (5.9) | 94% | — | 18 dic 2023 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension… |
| CVE-2023-5625 | Alta (7.5) | 0.80% | — | 1 nov 2023 | A regression was introduced in the Red Hat build of python-eventlet due to a change in the patch application strategy, resulting in a patch for CVE-2021-21419 not being applied for all builds of all products. |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
| CVE-2023-1636 | Media (5) | 0.48% | — | 24 sept 2023 | A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET… |
| CVE-2023-1633 | Media (5.5) | 0.19% | — | 24 sept 2023 | A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials. |
| CVE-2023-1625 | Media (5) | 0.71% | — | 24 sept 2023 | An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low… |
| CVE-2022-3596 | Alta (7.5) | 1.1% | — | 20 sept 2023 | An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising… |
| CVE-2022-3261 | Alta (7.5) | 0.29% | — | 15 sept 2023 | A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem. |
| CVE-2023-1108 | Alta (7.5) | 1.8% | — | 14 sept 2023 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
| CVE-2023-3637 | Media (6.5) | 1.3% | — | 25 jul 2023 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are… |
| CVE-2023-3354 | Alta (7.5) | 1.6% | — | 11 jul 2023 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection.… |
| CVE-2023-1668 | Alta (8.2) | 1.2% | — | 10 abr 2023 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace… |
| CVE-2022-3277 | Media (6.5) | 1.1% | — | 6 mar 2023 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are… |
| CVE-2022-3100 | Media (5.9) | 0.44% | — | 18 ene 2023 | A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API. |
| CVE-2022-23451 | Alta (8.1) | 1.3% | — | 6 sept 2022 | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This… |
| CVE-2022-2447 | Media (6.6) | 0.72% | — | 1 sept 2022 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote… |
| CVE-2022-23452 | Media (4.9) | 1.3% | — | 1 sept 2022 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and… |
| CVE-2022-2132 | Alta (8.6) | 2.2% | — | 31 ago 2022 | A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK. |
| CVE-2022-0718 | Media (4.9) | 1.7% | — | 29 ago 2022 | A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. |
| CVE-2021-3563 | Alta (7.4) | 1.7% | — | 26 ago 2022 | A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat… |
| CVE-2021-3979 | Media (6.5) | 0.56% | — | 25 ago 2022 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly passed in an encryption algorithm to create a non random key, which is weaker and can be exploited… |
| CVE-2020-14394 | Baja (3.2) | 0.39% | — | 17 ago 2022 | An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230