Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.6% | — | Openstack KeystoneCanonical Ubuntu Linux | 7/5/2020 | 17/6/2026 | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining admin while the user is on a limited viewer role. This potentially allows a malicious… | |
| Modificada | Media (6.8) | 1.6% | — | Redhat Ceph StorageRedhat OpenshiftRedhat OpenstackLinuxfoundation Ceph+1 | 13/4/2020 | 17/6/2026 | A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a… | |
| Modificada | Alta (7.8) | 0.32% | — | Suse Openstack CloudSuse Openstack Cloud Crowbar | 3/4/2020 | 17/6/2026 | An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue affects: SUSE OpenStack Cloud 7… | |
| Modificada | Media (5.6) | 0.71% | — | Redhat Ansible EngineRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 31/3/2020 | 17/6/2026 | A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections.… | |
| Modificada | Alta (7.1) | 0.33% | — | Redhat AnsibleRedhat Ansible TowerRedhat OpenstackDebian Linux+1 | 24/3/2020 | 17/6/2026 | A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by… | |
| Modificada | Media (4.7) | 0.36% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 16/3/2020 | 17/6/2026 | A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data… | |
| Modificada | Baja (3.9) | 0.40% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack | 16/3/2020 | 17/6/2026 | A flaw was found in Ansible Engine when the module package or service is used and the parameter 'use' is not specified. If a previous task is executed with a malicious user, the module sent can be selected by the attacker using the ansible facts file. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be… | |
| Modificada | Baja (3.3) | 0.40% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+1 | 16/3/2020 | 17/6/2026 | A flaw was found in Ansible Engine when a file is moved using atomic_move primitive as the file mode cannot be specified. This sets the destination files world-readable if the destination file does not exist and if the file exists, the file could be changed to have less restrictive permissions before the move. This… | |
| Modificada | Media (4.6) | 0.47% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 16/3/2020 | 17/6/2026 | A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable. | |
| Modificada | Baja (3.9) | 0.36% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 12/3/2020 | 17/6/2026 | A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on… | |
| Modificada | Alta (8.3) | 1.3% | — | Openstack Manila | 12/3/2020 | 17/6/2026 | OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares on such share networks. | |
| Modificada | Media (5) | 0.40% | — | Redhat AnsibleRedhat Ansible TowerRedhat Cloudforms Management EngineRedhat Openstack+2 | 11/3/2020 | 17/6/2026 | A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p… | |
| Modificada | Alta (7.5) | 2.2% | — | NokogiriRedhat Cloudforms Management EngineRedhat OpenshiftRedhat Openstack+4 | 19/2/2020 | 16/6/2026 | Nokogiri before 1.5.4 is vulnerable to XXE attacks | |
| Modificada | Baja (3.3) | 0.41% | — | Openstack Nova | 19/2/2020 | 17/6/2026 | An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to… | |
| Modificada | Media (6) | 4.0% | — | QemuRedhat OpenstackRedhat Enterprise LinuxDebian Linux+1 | 11/2/2020 | 17/6/2026 | An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Block (LBA) in an iscsi_co_block_status() routine. A remote user could use this flaw to crash the QEMU… | |
| Modificada | Crítica (9.8) | 2.7% | — | Golang GORedhat OpenstackRedhat Enterprise Linux | 8/2/2020 | 17/6/2026 | The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and Transfer-Encoding header fields. | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.94% | — | Suse Openstack CloudSuse Keystone-json-assignmentHP Helion Openstack | 17/1/2020 | 17/6/2026 | The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access, modify, create and delete arbitrary resources,… | |
| Modificada | Crítica (9.1) | 1.5% | — | Python-ecdsa Project Python-ecdsaRedhat Ceph StorageRedhat OpenstackRedhat Virtualization | 2/1/2020 | 17/6/2026 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create… | |
| Modificada | Media (5.5) | 0.40% | — | Openstack HorizonDebian Linux | 30/12/2019 | 16/6/2026 | Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value. | |
| Modificada | Media (5.5) | 0.34% | — | Redhat OpenstackOpenstack HorizonDebian LinuxFedoraproject Fedora | 30/12/2019 | 16/6/2026 | The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. | |
| Modificada | Alta (8.2) | 2.6% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 26/12/2019 | 17/6/2026 | In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in… | |
| Modificada | Alta (7.5) | 2.4% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 20/12/2019 | 17/6/2026 | Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding… | |
| Modificada | Alta (7.5) | 2.5% | — | Agendaless WaitressOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian LinuxFedoraproject Fedora+1 | 20/12/2019 | 17/6/2026 | Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if a front-end server does not parse… | |
| Modificada | Crítica (9.8) | 2.0% | — | Openstack Python-keystoneclientRedhat OpenstackDebian Linux | 10/12/2019 | 16/6/2026 | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass |