rpm package
suse/ardana-ansible&distro=HPE Helion OpenStack 8
pkg:rpm/suse/ardana-ansible&distro=HPE%20Helion%20OpenStack%208
Vulnerabilities (111)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-14856 | Med | 6.5 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Nov 26, 2019 | ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None | |
| CVE-2019-10217 | Med | 6.5 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Nov 25, 2019 | A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. An | |
| CVE-2019-11287 | Hig | 7.5 | < 8.0+git.1660773729.3789a6d-3.85.1 | 8.0+git.1660773729.3789a6d-3.85.1 | Nov 23, 2019 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP | |
| CVE-2019-10206 | Med | 6.5 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Nov 22, 2019 | ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger an | |
| CVE-2019-18874 | Hig | 7.5 | < 8.0+git.1589740980.6c3bcdc-3.73.1 | 8.0+git.1589740980.6c3bcdc-3.73.1 | Nov 12, 2019 | psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object. | |
| CVE-2019-14858 | Med | 5.5 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Oct 14, 2019 | A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub par | |
| CVE-2019-14846 | Hig | 7.8 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Oct 8, 2019 | In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not af | |
| CVE-2019-16865 | Hig | 7.5 | < 8.0+git.1589740980.6c3bcdc-3.73.1 | 8.0+git.1589740980.6c3bcdc-3.73.1 | Oct 4, 2019 | An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. | |
| CVE-2019-15043 | Hig | 7.5 | < 8.0+git.1566374355.c509923-3.67.3 | 8.0+git.1566374355.c509923-3.67.3 | Sep 3, 2019 | In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | |
| CVE-2019-15026 | Hig | 7.5 | < 8.0+git.1583432621.24fa60e-3.70.1 | 8.0+git.1583432621.24fa60e-3.70.1 | Aug 30, 2019 | memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c. | |
| CVE-2019-5477 | Cri | 9.8 | < 8.0+git.1566374355.c509923-3.67.3 | 8.0+git.1566374355.c509923-3.67.3 | Aug 16, 2019 | A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input a | |
| CVE-2019-10156 | Med | 5.4 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Jul 30, 2019 | A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any | |
| CVE-2019-0202 | Hig | 7.5 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Jul 26, 2019 | The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpo | |
| CVE-2018-11779 | Cri | 9.8 | < 8.0+git.1596735237.54109b1-3.77.1 | 8.0+git.1596735237.54109b1-3.77.1 | Jul 26, 2019 | In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class. | |
| CVE-2019-1010083 | Hig | 7.5 | < 8.0+git.1589740980.6c3bcdc-3.73.1 | 8.0+git.1589740980.6c3bcdc-3.73.1 | Jul 17, 2019 | The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656. | |
| CVE-2019-13611 | Hig | 8.8 | < 8.0+git.1566374355.c509923-3.67.3 | 8.0+git.1566374355.c509923-3.67.3 | Jul 16, 2019 | An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted. | |
| CVE-2019-0201 | Med | 5.9 | < 8.0+git.1583432621.24fa60e-3.70.1 | 8.0+git.1583432621.24fa60e-3.70.1 | May 23, 2019 | An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuth | |
| CVE-2019-11596 | Hig | 7.5 | < 8.0+git.1583432621.24fa60e-3.70.1 | 8.0+git.1583432621.24fa60e-3.70.1 | Apr 29, 2019 | In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c. | |
| CVE-2019-2628 | Med | 4.9 | < 8.0+git.1566374355.c509923-3.67.3 | 8.0+git.1566374355.c509923-3.67.3 | Apr 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compr | |
| CVE-2019-2627 | Med | 4.9 | < 8.0+git.1566374355.c509923-3.67.3 | 8.0+git.1566374355.c509923-3.67.3 | Apr 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with networ |
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. An
- affected < 8.0+git.1660773729.3789a6d-3.85.1fixed 8.0+git.1660773729.3789a6d-3.85.1
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger an
- affected < 8.0+git.1589740980.6c3bcdc-3.73.1fixed 8.0+git.1589740980.6c3bcdc-3.73.1
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters marked as no_log, passing an invalid parameter name to the module will cause the task to fail before the no_log options in the sub par
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level which lead to a disclosure of credentials if a plugin used a library that logged credentials at the DEBUG level. This flaw does not af
- affected < 8.0+git.1589740980.6c3bcdc-3.73.1fixed 8.0+git.1589740980.6c3bcdc-3.73.1
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
- affected < 8.0+git.1566374355.c509923-3.67.3fixed 8.0+git.1566374355.c509923-3.67.3
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
- affected < 8.0+git.1583432621.24fa60e-3.70.1fixed 8.0+git.1583432621.24fa60e-3.70.1
memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.
- affected < 8.0+git.1566374355.c509923-3.67.3fixed 8.0+git.1566374355.c509923-3.67.3
A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input a
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
A flaw was discovered in the way Ansible templating was implemented in versions before 2.6.18, 2.7.12 and 2.8.2, causing the possibility of information disclosure through unexpected variable substitution. By taking advantage of unintended variable substitution the content of any
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-incubating to 1.2.2, it is possible to read files off the host's file system that were not intended to be accessible via these endpo
- affected < 8.0+git.1596735237.54109b1-3.77.1fixed 8.0+git.1596735237.54109b1-3.77.1
In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI daemon to deserialize user provided bytes into a Java class.
- affected < 8.0+git.1589740980.6c3bcdc-3.73.1fixed 8.0+git.1589740980.6c3bcdc-3.73.1
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
- affected < 8.0+git.1566374355.c509923-3.67.3fixed 8.0+git.1566374355.c509923-3.67.3
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
- affected < 8.0+git.1583432621.24fa60e-3.70.1fixed 8.0+git.1583432621.24fa60e-3.70.1
An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuth
- affected < 8.0+git.1583432621.24fa60e-3.70.1fixed 8.0+git.1583432621.24fa60e-3.70.1
In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.
- affected < 8.0+git.1566374355.c509923-3.67.3fixed 8.0+git.1566374355.c509923-3.67.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compr
- affected < 8.0+git.1566374355.c509923-3.67.3fixed 8.0+git.1566374355.c509923-3.67.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows high privileged attacker with networ
Page 4 of 6