Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Openstack HIGH 7.8
CVE-2019-3830

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data t…

Fix: after 2015.1.4
Fix from $1,950 2019-03-26
Openstack HIGH 7.5
CVE-2018-16856

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.…

Fix: 2.0.2-5 / 3.0.1-0.20181009115732+
Fix from $1,950 2019-03-26
Ceph HIGH 7.5
CVE-2018-16889

Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files …

Fix: after 13.2.4
Fix from $1,950 2019-01-28
Openstack MEDIUM 5.5
CVE-2017-2621

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improp…

Fix: 8.0.0+
Fix from $1,600 2018-07-27
Virtualization MEDIUM 6.6
CVE-2017-15113

ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change th…

Fix: 4.1.7.6+
Fix from $1,600 2018-07-27
Ansible Engine MEDIUM 5.9
CVE-2018-10855

Ansible 2.5 prior to 2.5.5, and 2.4 prior to 2.4.5, do not honor the no_log task flag for failed tasks. When the no_log flag has been used to protect…

Fix: 2.4.5+
Fix from $1,600 2018-07-03
Enterprise Virtualization Manager CRITICAL 9.8
CVE-2018-1072

ovirt-engine before version ovirt 4.2.2 is vulnerable to an information exposure through log files. When engine-backup was run with one of the option…

Fix: 4.2.2+
Fix from $2,300 2018-06-26
Enterprise Virtualization CRITICAL 9.8
CVE-2018-1117

ovirt-ansible-roles before version 1.0.6 has a vulnerability due to a missing no_log directive, resulting in the 'Add oVirt Provider to ManageIQ/Clou…

Fix: 1.0.6+
Fix from $2,300 2018-06-20
Ansible CRITICAL 9.8
CVE-2017-7550

A flaw was found in the way Ansible (2.3.x before 2.3.3, and 2.4.x before 2.4.1) passed certain parameters to the jenkins_plugin module. Remote attac…

Fix: 2.3.3 / 2.4.1+
Fix from $2,300 2017-11-21
Enterprise Virtualization MEDIUM 5.5
CVE-2016-4443

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by r…

Patch available
Fix from $1,600 2016-12-14