rpm package
suse/openstack-heat-templates&distro=SUSE OpenStack Cloud Crowbar 8
pkg:rpm/suse/openstack-heat-templates&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208
Vulnerabilities (65)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-16786 | Hig | 7.1 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Dec 20, 2019 | Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separ | |
| CVE-2019-16785 | Hig | 7.1 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Dec 20, 2019 | Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if | |
| CVE-2019-16770 | Med | 5.3 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Dec 5, 2019 | In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait p | |
| CVE-2019-11287 | Hig | 7.5 | < 0.0.0+git.1654529662.75fa04a-3.27.1 | 0.0.0+git.1654529662.75fa04a-3.27.1 | Nov 23, 2019 | Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP | |
| CVE-2019-18874 | Hig | 7.5 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Nov 12, 2019 | psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object. | |
| CVE-2019-2974 | Med | 6.5 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Oct 16, 2019 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mult | |
| CVE-2019-2938 | Med | 4.4 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Oct 16, 2019 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromi | |
| CVE-2017-1002201 | Med | 6.1 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Oct 15, 2019 | In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially e | |
| CVE-2019-16865 | Hig | 7.5 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Oct 4, 2019 | An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image. | |
| CVE-2019-15043 | Hig | 7.5 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Sep 3, 2019 | In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana. | |
| CVE-2019-2805 | Med | 6.5 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mu | |
| CVE-2019-2758 | Med | 5.5 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compr | |
| CVE-2019-2740 | Med | 6.5 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multi | |
| CVE-2019-2739 | Med | 5.1 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon | |
| CVE-2019-2737 | Med | 4.9 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 23, 2019 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network acc | |
| CVE-2019-1010083 | Hig | 7.5 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Jul 17, 2019 | The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656. | |
| CVE-2019-13117 | Med | 5.3 | < 0.0.0+git.1560033670.e3b5a52-3.12.3 | 0.0.0+git.1560033670.e3b5a52-3.12.3 | Jul 1, 2019 | In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character. | |
| CVE-2019-3828 | Med | 4.2 | < 0.0.0+git.1582270132.8a20477-3.15.1 | 0.0.0+git.1582270132.8a20477-3.15.1 | Mar 27, 2019 | Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path. | |
| CVE-2018-1000808 | Med | 5.9 | < 0.0.0+git.1553459627.948e8cc-3.9.2 | 0.0.0+git.1553459627.948e8cc-3.9.2 | Oct 8, 2018 | Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploit | |
| CVE-2018-1000807 | Hig | 8.1 | < 0.0.0+git.1553459627.948e8cc-3.9.2 | 0.0.0+git.1553459627.948e8cc-3.9.2 | Oct 8, 2018 | Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitab |
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separ
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait p
- affected < 0.0.0+git.1654529662.75fa04a-3.27.1fixed 0.0.0+git.1654529662.75fa04a-3.27.1
Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mult
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromi
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially e
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
In Grafana 2.x through 6.x before 6.3.4, parts of the HTTP API allow unauthenticated use. This makes it possible to run a denial of service attack against the server running Grafana.
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via mu
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compr
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multi
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network acc
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
- affected < 0.0.0+git.1560033670.e3b5a52-3.12.3fixed 0.0.0+git.1560033670.e3b5a52-3.12.3
In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
- affected < 0.0.0+git.1582270132.8a20477-3.15.1fixed 0.0.0+git.1582270132.8a20477-3.15.1
Ansible fetch module before versions 2.5.15, 2.6.14, 2.7.8 has a path traversal vulnerability which allows copying and overwriting files outside of the specified destination in the local ansible controller host, by not restricting an absolute path.
- affected < 0.0.0+git.1553459627.948e8cc-3.9.2fixed 0.0.0+git.1553459627.948e8cc-3.9.2
Python Cryptographic Authority pyopenssl version Before 17.5.0 contains a CWE - 401 : Failure to Release Memory Before Removing Last Reference vulnerability in PKCS #12 Store that can result in Denial of service if memory runs low or is exhausted. This attack appear to be exploit
- affected < 0.0.0+git.1553459627.948e8cc-3.9.2fixed 0.0.0+git.1553459627.948e8cc-3.9.2
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitab
Page 3 of 4