VYPR

rpm package

suse/release-notes-hpe-helion-openstack&distro=HPE Helion OpenStack 8

pkg:rpm/suse/release-notes-hpe-helion-openstack&distro=HPE%20Helion%20OpenStack%208

Vulnerabilities (67)

  • CVE-2016-8647Jul 26, 2018
    affected < 8.20200922-3.23.1fixed 8.20200922-3.23.1

    An input validation vulnerability was found in Ansible's mysql_user module before 2.2.1.0, which may fail to correctly change a password in certain circumstances. Thus the previous password would still be active when it should have been changed.

  • CVE-2018-10875Jul 13, 2018
    affected < 8.20200922-3.23.1fixed 8.20200922-3.23.1

    A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

  • CVE-2017-7466Jun 22, 2018
    affected < 8.20200922-3.23.1fixed 8.20200922-3.23.1

    Ansible before version 2.3 has an input validation vulnerability in the handling of data sent from client systems. An attacker with control over a client system being managed by Ansible, and the ability to send facts back to the Ansible server, could use this flaw to execute arbi

  • CVE-2016-9587Apr 24, 2018
    affected < 8.20200922-3.23.1fixed 8.20200922-3.23.1

    Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use thi

  • CVE-2017-7550CriNov 21, 2017
    affected < 8.20200922-3.23.1fixed 8.20200922-3.23.1

    A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attackers could use this flaw to expose sensitive information from a remote host's logs. This flaw was fixed by not allowing passwords t

  • CVE-2016-10127CriMar 3, 2017
    affected < 8.20190911-3.20.3fixed 8.20190911-3.20.3

    PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

  • CVE-2015-3448Apr 29, 2015
    affected < 8.20190911-3.20.3fixed 8.20190911-3.20.3

    REST client for Ruby (aka rest-client) before 1.7.3 logs usernames and passwords, which allows local users to obtain sensitive information by reading the log.

Page 4 of 4