Where
-Infinity
0
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

An XML eXternal Entity (XXE) flaw was found in Nokogiri, a Ruby gem for parsing HTML, XML, and SAX. Using external XML entities, a remote attacker could specify a URL in a specially crafted XML that, when parsed, would cause a connection to that URL to be opened.

A patch shipped with the 1.5.4 release of Nokogiri provided a "nonet" option to disable external connections. However, local file URLs could still be used to exploit this flaw. The 1.6.4 release of Nokogiri fixed this issue by using libxml2 2.9.0.

Additional information is detailed at:

https://github.com/sparklemotion/nokogiri/issues/693#issuecomment-68334768

CVE request and assignment:

http://seclists.org/oss-sec/2015/q1/57

1 / 2
Source: Red Hat
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> Incomplete fix for CVE-2023-39325/CVE-2023-44487 in OpenStack Platform</li> (CVE-2024-4438)<br><li> Incomplete fix for CVE-2021-44716 in OpenStack Platform (CVE-2024-4437)</li> <li> Incomplete fix for CVE-2022-41723 in OpenStack Platform (CVE-2024-4436)</li> <li> golang: net/http, x/net/http2: unlimited number of CONTINUATION frames causes DoS (CVE-2023-45288)</li> <li> golang: net/http/internal: Denial of Service (DoS) via Resource Consumption via HTTP requests (CVE-2023-39326)</li> <li> golang: crypto/tls: lack of a limit on buffered post-handshake (CVE-2023-39322)</li> <li> golang: crypto/tls: panic when processing post-handshake message on QUIC connections (CVE-2023-39321)</li> <li> golang: html/template: improper handling of special tags within script contexts (CVE-2023-39319)</li> <li> golang: html/template: improper handling of HTML-like comments within script contexts (CVE-2023-39318</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Gunicorn (Green Unicorn) is a Python WSGI HTTP server for UNIX.<br>Security Fix(es):<br><li> HTTP Request Smuggling due to improper validation of Transfer-Encoding</li> headers (CVE-2024-1135)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Affected components:<br><li> python-yaql: a library that contains a large set of commonly used functions</li> <li> openstack-tripleo-heat-templates: Heat templates for TripleO</li> <li> openstack-tripleo-common: Python library for code used by TripleO projects</li> Security Fix(es):<br><li> OpenStack Murano Component Information Leakage (CVE-2024-29156)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.1.9 (openstack-nova) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

A highly-available key value store for shared configuration<br>Security Fix(es):<br><li> golang: Calling Decoder.Decode on a message which contains deeply nested</li> structures can cause a panic due to stack exhaustion (CVE-2024-34156)<br>For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7
Race Condition

Important: Red Hat OpenStack Platform 16.2 (python-waitress) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
7

Important: Red Hat OpenStack Platform 16.2 (openstack-ironic) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes<br>described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: Red Hat OpenStack Platform 16.2.6 (python-twisted) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Moderate: Red Hat OpenStack Platform 16.1.9 (python-twisted) security update

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

A high-level Python Web framework<br>Security Fix(es):<br><li> python-django20: jquery: Untrusted code execution via &lt;option&gt; tag in HTML passed to DOM manipulation methods (CVE-2020-11023)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.

1 / 2
Source: Red Hat

Remedy

For details on how to apply this update, which includes the changes described in this advisory, refer to:<br><a href="https://access.redhat.com/articles/11258" target="_blank">https://access.redhat.com/articles/11258</a>
First published (updated )
Severity
4

Plain password from RHSM in the logs during OSP13 deployment with subscription-manager. overcloudinstall.log contains a plaintext password after overcloud creation. See https://bugzilla.redhat.com/showbug.cgi?id=1961709

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203