Red Hat OpenStack For IBM Power 16.1

CPE Details

Red Hat OpenStack For IBM Power 16.1
16.1
2022-10-07
10h59 +00:00
2022-11-09
15h47 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:openstack_for_ibm_power:16.1:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

openstack_for_ibm_power

Version

16.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-3101 2023-03-23 00h00 +00:00 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
5.5
Medium
CVE-2022-3146 2023-03-23 00h00 +00:00 A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
5.5
Medium
CVE-2022-3100 2023-01-17 23h00 +00:00 A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
5.9
Medium
CVE-2020-9490 2020-08-07 13h24 +00:00 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
7.5
High