Openstack
openstack
277 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (277)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept n...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesMay 6, 2026 Apr 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb mid...Show more |
1Openstack 1Image Registry And Delivery Service (glance) May 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by re...Show more |
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary fil...Show more |
1Openstack 1Tripleo Heat Templates May 6, 2026 Apr 11, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the...Show more |
2Openstack Oracle3Keystone KeystonemiddlewareSolarisMay 6, 2026 Feb 3, 2016 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not...Show more |
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource co...Show more |
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted request...Show more |
4Fedoraproject OpenstackOracle+1 more4Fedora OpenstackOrchestration Api+1 moreMay 6, 2026 Jan 20, 2016 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine...Show more |
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen ba...Show more |
2Fedoraproject Openstack2Fedora Swift3May 6, 2026 Jan 13, 2016 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header. |
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by ov...Show more |
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error. |
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance tha...Show more |
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing...Show more |
1Openstack 1Image Registry And Delivery Service (glance) May 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting image...Show more |
1Openstack 1Image Registry And Delivery Service (glance) May 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 5.5 MEDIUM· v2 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-s...Show more |
OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container. |
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consum...Show more |
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, networ...Show more |