Known Vulnerabilities for Openstack Platform by Redhat
Listed below are 10 of the newest known vulnerabilities associated with "Openstack Platform" by "Redhat".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-23452 | An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different proje... | 4.9 - MEDIUM | 2022-09-01 | 2023-02-12 |
| CVE-2022-23451 | An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authe... | 8.1 - HIGH | 2022-09-06 | 2023-02-12 |
| CVE-2021-20270 | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlight... | 7.5 - HIGH | 2021-03-23 | 2021-12-10 |
| CVE-2021-20267 | A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in ... | 7.1 - HIGH | 2021-05-28 | 2022-10-07 |
| CVE-2021-20257 | An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) desc... | 6.5 - MEDIUM | 2022-03-16 | 2023-02-12 |
| CVE-2021-3979 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly pass... | 6.5 - MEDIUM | 2022-08-25 | 2023-10-23 |
| CVE-2021-3654 | A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redir... | 6.1 - MEDIUM | 2022-03-02 | 2023-05-03 |
| CVE-2021-3563 | A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers... | 7.4 - HIGH | 2022-08-26 | 2024-01-21 |
| CVE-2020-10731 | A flaw was found in the nova_libvirt container provided by the Red Hat OpenStack Platform 16, where it does not have SELinux ... | 9.9 - CRITICAL | 2020-07-31 | 2021-10-19 |
| CVE-2020-1690 | An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user... | 6.5 - MEDIUM | 2021-06-07 | 2022-07-25 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Openstack Platform | 16.1 | All | All | All |
| Application | Redhat | Openstack Platform | 16.0 | All | All | All |
| Application | Redhat | Openstack Platform | 15.0 | All | All | All |
| Application | Redhat | Openstack Platform | 13.0 | All | All | All |
| Application | Redhat | Openstack Platform | 12.0 | All | All | All |
| Application | Redhat | Openstack Platform | 10.0 | All | All | All |