Vulnerabilities > Redhat > Openstack > 4.0

DATE CVE VULNERABILITY TITLE RISK
2020-02-19 CVE-2012-6685 XML Entity Expansion vulnerability in multiple products
Nokogiri before 1.5.4 is vulnerable to XXE attacks
network
low complexity
nokogiri redhat CWE-776
5.0
2019-12-10 CVE-2013-1793 Missing Authentication for Critical Function vulnerability in Redhat Openstack and Openstack Essex
openstack-utils openstack-db has insecure password creation
network
low complexity
redhat CWE-306
5.0
2019-11-05 CVE-2013-6461 XML Entity Expansion vulnerability in multiple products
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
4.3
2019-11-05 CVE-2013-6460 XML Entity Expansion vulnerability in multiple products
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
4.3
2019-11-01 CVE-2013-2255 Improper Certificate Validation vulnerability in multiple products
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
4.3
2015-01-07 CVE-2014-9493 Permissions, Privileges, and Access Controls vulnerability in multiple products
The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete arbitrary files via a full pathname in a file: URL in the image location property.
network
low complexity
redhat openstack CWE-264
5.5
2014-08-19 CVE-2014-4615 Information Exposure vulnerability in multiple products
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
network
low complexity
redhat canonical openstack CWE-200
5.0
2014-06-02 CVE-2013-6470 Improper Authentication vulnerability in Redhat Openstack 4.0
The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenStack Platform 4.0, disables authentication for Qpid, which allows remote attackers to gain access by connecting to Qpid.
network
low complexity
redhat CWE-287
5.0
2014-04-17 CVE-2014-0071 Permissions, Privileges, and Access Controls vulnerability in Redhat Openstack 4.0
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.
network
low complexity
redhat CWE-264
6.4
2014-02-06 CVE-2013-6393 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.
6.8