VYPR

rpm package

suse/openstack-swift&distro=SUSE OpenStack Cloud 9

pkg:rpm/suse/openstack-swift&distro=SUSE%20OpenStack%20Cloud%209

Vulnerabilities (6)

  • CVE-2023-1625Sep 24, 2023
    affected < 2.19.3~dev3-3.6.3fixed 2.19.3~dev3-3.6.3

    An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the

  • CVE-2023-25577Feb 14, 2023
    affected < 2.19.3~dev3-3.6.3fixed 2.19.3~dev3-3.6.3

    Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a small amount of bytes, but each requires CPU time to parse and may use more memory

  • CVE-2022-47950Jan 18, 2023
    affected < 2.19.3~dev3-3.6.3fixed 2.19.3~dev3-3.6.3

    An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentiall

  • CVE-2018-17954Apr 3, 2020
    affected < 2.19.2~dev48-3.3.1fixed 2.19.2~dev48-3.3.1

    An Improper Privilege Management in crowbar of SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud 9, SUSE OpenStack Cloud Crowbar 8, SUSE OpenStack Cloud Crowbar 9 allows root users on any crowbar managed node to cause become root on any other node. This issue a

  • CVE-2019-16770Dec 5, 2019
    affected < 2.19.2~dev48-3.3.1fixed 2.19.2~dev48-3.3.1

    In Puma before versions 3.12.2 and 4.3.1, a poorly-behaved client could use keepalive requests to monopolize Puma's reactor and create a denial of service attack. If more keepalive connections to Puma are opened than there are threads available, additional connections will wait p

  • CVE-2019-13117Jul 1, 2019
    affected < 2.19.2~dev48-3.3.1fixed 2.19.2~dev48-3.3.1

    In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.