Search CVE reports
151 – 160 of 42041 results
In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased by another project.
1 affected package
ironic
| Package | 24.04 LTS |
|---|---|
| ironic | Needs evaluation |
It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive resource usage and potential denial of service. This issue affects Apache Qpid...
1 affected package
qpid-proton
| Package | 24.04 LTS |
|---|---|
| qpid-proton | Needs evaluation |
An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0,...
1 affected package
qpid-proton
| Package | 24.04 LTS |
|---|---|
| qpid-proton | Needs evaluation |
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version...
1 affected package
qpid-proton
| Package | 24.04 LTS |
|---|---|
| qpid-proton | Needs evaluation |
In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed...
1 affected package
swift
| Package | 24.04 LTS |
|---|---|
| swift | Needs evaluation |
In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned...
1 affected package
swift
| Package | 24.04 LTS |
|---|---|
| swift | Needs evaluation |
In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS). The "qdtext" pattern (?:[^"]|\\.)* allows an unauthenticated remote attacker...
1 affected package
swift
| Package | 24.04 LTS |
|---|---|
| swift | Needs evaluation |
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade...
1 affected package
qpid-proton
| Package | 24.04 LTS |
|---|---|
| qpid-proton | Needs evaluation |
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to...
1 affected package
qpid-proton
| Package | 24.04 LTS |
|---|---|
| qpid-proton | Needs evaluation |
In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating...
1 affected package
neutron
| Package | 24.04 LTS |
|---|---|
| neutron | Needs evaluation |