← Back

Opendev

opendev

2 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Octavia
octavia
Sushy Tools
sushy-tools
Virtualbmc
virtualbmc

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Opendev
3Fedora
Sushy ToolsVirtualbmc
Jun 17, 2026
Oct 30, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NO...Show more
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."Show less
2Canonical
Opendev
2Octavia
Ubuntu Linux
Jun 17, 2026
Oct 8, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue...Show more
Amphora Images in OpenStack Octavia >=0.10.0 <2.1.2, >=3.0.0 <3.2.0, >=4.0.0 <4.1.0 allows anyone with access to the management network to bypass client-certificate based authentication and retrieve information or issue configuration commands via simple HTTP requests to the Agent on port https/9443, because the cmd/agent.py gunicorn cert_reqs option is True but is supposed to be ssl.CERT_REQUIRED.Show less