Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Redhat CephRedhat Ceph StorageFedoraproject FedoraDebian Linux | 17/5/2021 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response… | |
| Modificada | Alta (7.2) | 2.1% | — | Linuxfoundation CephRedhat Ceph StorageFedoraproject FedoraDebian Linux | 15/4/2021 | 17/6/2026 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another… | |
| Modificada | Media (4.4) | 0.27% | — | Redhat CephRedhat Ceph StorageFedoraproject Fedora | 8/1/2021 | 17/6/2026 | A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible. | |
| Modificada | Alta (7.1) | 0.31% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformRedhat Openstack Platform+1 | 18/12/2020 | 17/6/2026 | User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx user, including existing users. The access key is retrieved via the interface drivers. Then, all… | |
| Modificada | Media (5.5) | 0.21% | — | Ceph-ansibleRedhat Ceph Storage | 8/12/2020 | 17/6/2026 | A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (8.8) | 1.0% | — | Redhat CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora | 23/11/2020 | 17/6/2026 | A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a… | |
| Modificada | Media (6.1) | 1.3% | — | Encode Django Rest FrameworkRedhat Ceph StorageDebian Linux | 30/9/2020 | 17/6/2026 | A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This allows a user who can control those strings to inject malicious <script> tags, leading to a… | |
| Modificada | Alta (7.1) | 0.23% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Openstack Platform+1 | 23/9/2020 | 17/6/2026 | A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw leads to malicious… | |
| Modificada | Media (6.5) | 1.6% | — | Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+2 | 26/6/2020 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.… | |
| Modificada | Alta (8) | 0.65% | — | Linuxfoundation Ceph | 22/6/2020 | 17/6/2026 | An authorization bypass vulnerability was found in Ceph versions 15.2.0 before 15.2.2, where the ceph-mon and ceph-mgr daemons do not properly restrict access, resulting in gaining access to unauthorized resources. This flaw allows an authenticated client to modify the configuration and possibly conduct further… | |
| Modificada | Media (5.5) | 0.36% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Openstack+2 | 11/5/2020 | 17/6/2026 | A flaw was found in Ansible Engine affecting Ansible Engine versions 2.7.x before 2.7.17 and 2.8.x before 2.8.11 and 2.9.x before 2.9.7 as well as Ansible Tower before and including versions 3.4.5 and 3.5.5 and 3.6.3 when using modules which decrypts vault files such as assemble, script, unarchive, win_copy, aws_s3 or… | |
| Modificada | Media (5.5) | 0.47% | — | GrafanaRedhat Ceph StorageRedhat Enterprise LinuxFedoraproject Fedora | 29/4/2020 | 17/6/2026 | An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords). | |
| Modificada | Media (6.1) | 1.6% | — | Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+2 | 23/4/2020 | 17/6/2026 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. | |
| Modificada | Alta (7.5) | 2.7% | — | Linuxfoundation CephCanonical Ubuntu Linux | 22/4/2020 | 17/6/2026 | An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception. | |
| Modificada | Alta (7.5) | 2.1% | — | Linuxfoundation CephRedhat Ceph Storage | 21/4/2020 | 17/6/2026 | A path traversal flaw was found in the Ceph dashboard implemented in upstream versions v14.2.5, v14.2.6, v15.0.0 of Ceph storage and has been fixed in versions 14.2.7 and 15.1.0. An unauthenticated attacker could use this flaw to cause information disclosure on the host machine running the Ceph dashboard. | |
| Modificada | Media (6.8) | 1.6% | — | Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+1 | 13/4/2020 | 17/6/2026 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a… | |
| Modificada | Alta (7.8) | 0.46% | — | Systemd Project SystemdRedhat Ceph StorageRedhat DiscoveryRedhat Migration Toolkit+3 | 31/3/2020 | 17/6/2026 | A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash systemd services or potentially execute code and elevate their privileges, by sending specially… | |
| Modificada | Media (5.6) | 0.71% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 31/3/2020 | 17/6/2026 | A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.… | |
| Modificada | Media (6.5) | 2.4% | — | CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux | 7/2/2020 | 17/6/2026 | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT… | |
| Modificada | Media (6.5) | 1.9% | — | Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 2/1/2020 | 17/6/2026 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data. | |
| Modificada | Crítica (9.1) | 1.5% | — | Python-ecdsa Project Python-ecdsaRedhat Ceph StorageRedhat OpenstackRedhat Virtualization | 2/1/2020 | 17/6/2026 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Ceph Storage | 23/12/2019 | 17/6/2026 | A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server. | |
| Modificada | Media (5.5) | 0.30% | — | MI Cepheus Firmware | 14/11/2019 | 17/6/2026 | The Xiaomi Cepheus Android device with a build fingerprint of Xiaomi/cepheus/cepheus:9/PKQ1.181121.001/V10.2.6.0.PFAMIXM:user/release-keys contains a pre-installed app with a package name of com.qualcomm.qti.callenhancement app (versionCode=28, versionName=9) that allows unauthorized microphone audio recording via a… | |
| Modificada | Alta (7.5) | 4.5% | — | CephRedhat Ceph StorageFedoraproject Fedora | 8/11/2019 | 17/6/2026 | A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients. | |
| Analizada | Alta (7.5) | 2.9% | — | Ceph CivetwebCanonical Ubuntu Linux | 27/3/2019 | 17/6/2026 | A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of service. |