|
248851
|
7.2 |
HIGH
Network
|
redhat
|
openstack
|
An authorization-check flaw was discovered in federation configurations of the OpenStack Identity service (keystone). An authenticated federated user could request permissions to a project and uninte…
|
-
|
CVE-2017-2673
|
2024-11-21 12:23 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248852
|
6.5 |
MEDIUM
Network
|
infinispan redhat
|
infinispan jboss_data_grid
|
It was found that the REST API in Infinispan before version 9.0.0 did not properly enforce auth constraints. An attacker could use this vulnerability to read or modify data in the default cache or a …
|
CWE-287
Improper Authentication
|
CVE-2017-2638
|
2024-11-21 12:23 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248853
|
7.0 |
HIGH
Local
|
mongodb redhat
|
mongodb storage_console
|
The skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.conf file which is owned by root but read by local user. An…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-2665
|
2024-11-21 12:23 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248854
|
9.1 |
CRITICAL
Network
|
qemu redhat citrix debian xen
|
qemu enterprise_linux_desktop xenserver enterprise_linux_workstation openstack enterprise_linux_server debian_linux enterprise_linux_server_aus enterprise_linux_server_eus …
|
Quick emulator (QEMU) built with the Cirrus CLGD 54xx VGA emulator support is vulnerable to an out-of-bounds access issue. It could occur while copying VGA data via bitblt copy in backward mode. A pr…
|
-
|
CVE-2017-2615
|
2024-11-21 12:23 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248855
|
6.5 |
MEDIUM
Network
|
fedoraproject redhat
|
389_directory_server enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to m…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-2668
|
2024-11-21 12:23 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248856
|
8.8 |
HIGH
Network
|
theforeman redhat
|
foreman satellite
|
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned system…
|
CWE-269
Improper Privilege Management
|
CVE-2017-2672
|
2024-11-21 12:23 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248857
|
7.5 |
HIGH
Network
|
dovecot debian
|
dovecot debian_linux
|
Dovecot before version 2.2.29 is vulnerable to a denial of service. When 'dict' passdb and userdb were used for user authentication, the username sent by the IMAP/POP3 client was sent through var_exp…
|
CWE-20
Improper Input Validation
|
CVE-2017-2669
|
2024-11-21 12:23 |
2018-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248858
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkins and the stored secrets vulnerable to unnecessary risks (SECURITY-304).
|
CWE-326
Inadequate Encryption Strength
|
CVE-2017-2598
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248859
|
7.8 |
HIGH
Local
|
hawt.io
|
hawtio
|
hawtio before version 1.5.5 is vulnerable to remote code execution via file upload. An attacker could use this vulnerability to upload a crafted file which could be executed on a target machine where…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-2617
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248860
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
jenkins before versions 2.44, 2.32.2 is vulnerable to an information disclosure vulnerability in search suggestions (SECURITY-385). The autocomplete feature on the search box discloses the names of t…
|
CWE-200
Information Exposure
|
CVE-2017-2609
|
2024-11-21 12:23 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|