Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown
CVE-2020-1760
Disclosure Date: April 23, 2020 (last updated February 21, 2025)
A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
0
Attacker Value
Unknown
CVE-2020-1759
Disclosure Date: April 13, 2020 (last updated February 21, 2025)
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.
0
Attacker Value
Unknown
CVE-2019-14905
Disclosure Date: March 31, 2020 (last updated February 21, 2025)
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.
0
Attacker Value
Unknown
CVE-2019-14859
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create false transactions.
0
Attacker Value
Unknown
CVE-2019-14864
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data.
0
Attacker Value
Unknown
CVE-2019-19337
Disclosure Date: December 23, 2019 (last updated November 27, 2024)
A flaw was found in Red Hat Ceph Storage version 3 in the way the Ceph RADOS Gateway daemon handles S3 requests. An authenticated attacker can abuse this flaw by causing a remote denial of service by sending a specially crafted HTTP Content-Length header to the Ceph RADOS Gateway server.
0
Attacker Value
Unknown
CVE-2019-10222
Disclosure Date: November 08, 2019 (last updated October 24, 2023)
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
0
Attacker Value
Unknown
CVE-2018-14662
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph disk encryption.
0
Attacker Value
Unknown
CVE-2018-16846
Disclosure Date: January 15, 2019 (last updated November 27, 2024)
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial of service against OMAPs holding bucket indices.
0
Attacker Value
Unknown
CVE-2018-19039
Disclosure Date: December 13, 2018 (last updated November 27, 2024)
Grafana before 4.6.5 and 5.x before 5.3.3 allows remote authenticated users to read arbitrary files by leveraging Editor or Admin permissions.
0