VYPR

rpm package

suse/python-manila-tempest-plugin&distro=SUSE OpenStack Cloud Crowbar 9

pkg:rpm/suse/python-manila-tempest-plugin&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Vulnerabilities (8)

  • CVE-2020-9543Mar 12, 2020
    affected < 0.1.0-3.6.1fixed 0.1.0-3.6.1

    OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as shared file systems and groups of shares o

  • CVE-2020-5247Feb 28, 2020
    affected < 0.1.0-3.6.1fixed 0.1.0-3.6.1

    In Puma (RubyGem) before 4.3.2 and before 3.12.3, if an application using Puma allows untrusted input in a response header, an attacker can use newline characters (i.e. `CR`, `LF` or`/r`, `/n`) to end the header and inject malicious content, such as additional headers or an entir

  • CVE-2019-15026Aug 30, 2019
    affected < 0.1.0-3.6.1fixed 0.1.0-3.6.1

    memcached 1.5.16, when UNIX sockets are used, has a stack-based buffer over-read in conn_to_str in memcached.c.

  • CVE-2019-0201May 23, 2019
    affected < 0.1.0-3.6.1fixed 0.1.0-3.6.1

    An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuth

  • CVE-2019-11596Apr 29, 2019
    affected < 0.1.0-3.6.1fixed 0.1.0-3.6.1

    In memcached before 1.5.14, a NULL pointer dereference was found in the "lru mode" and "lru temp_ttl" commands. This causes a denial of service when parsing crafted lru command messages in process_lru_command in memcached.c.

  • CVE-2019-11068Apr 10, 2019
    affected < 0.1.0-3.3.5fixed 0.1.0-3.3.5

    libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.

  • CVE-2019-10876Apr 5, 2019
    affected < 0.1.0-3.3.5fixed 0.1.0-3.3.5

    An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes

  • CVE-2018-19039Dec 13, 2018
    affected < 0.1.0-3.3.5fixed 0.1.0-3.3.5

    Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.