← Back

Openstack

openstack

277 CVEs • 65 products

Products (65)

Click to collapse
Toggle
Keystone
keystone
Nova
nova
Folsom
folsom
Neutron
neutron
Horizon
horizon
Essex
essex
Swift
swift
Grizzly
grizzly
Compute
compute
Glance
glance
Havana
havana
Cinder
cinder
Ironic
ironic
Heat
heat
Barbican
barbican
Icehouse
icehouse
Trove
trove
Diablo
diablo
Ceilometer
ceilometer
Oslo
oslo
Murano
murano
Manila
manila
Designate
designate
Octavia
octavia
Magnum
magnum
Cinder Folsom
cinder_folsom
Devstack
devstack
Pycadf
pycadf
Juno
juno
Kilo
kilo
Swift3
swift3
Mitaka Murano
mitaka-murano
Compute (nova)
compute_(nova)
Puppet Gerrit
puppet-gerrit
Nova Lxd
nova-lxd
Openstack
openstack
Swauth
swauth
Puppet Tripleo
puppet-tripleo
Puppet Swift
puppet-swift
Tripleo Common
tripleo-common
Os Vif
os-vif
Oslo.utils
oslo.utils
Kolla
kolla
Glance Store
glance-store
Yaql
yaql
Vitrage
vitrage

CVEs (277)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openstack
1Neutron
May 6, 2026
Jun 17, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept n...Show more
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local source address.Show less
2Openstack
Redhat
2Openstack
Tripleo Heat Templates
May 6, 2026
Apr 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb mid...Show more
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.Show less
1Openstack
1Image Registry And Delivery Service (glance)
May 6, 2026
Apr 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by re...Show more
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.Show less
1Openstack
1Nova
May 6, 2026
Apr 12, 2016
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary fil...Show more
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.Show less
1Openstack
1Tripleo Heat Templates
May 6, 2026
Apr 11, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the...Show more
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.Show less
2Openstack
Oracle
3Keystone
KeystonemiddlewareSolaris
May 6, 2026
Feb 3, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not...Show more
The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows remote authenticated users to bypass intended access restrictions and gain access to cloud resources by manipulating byte fields within a revoked token.Show less
1Openstack
1Swift
May 6, 2026
Jan 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource co...Show more
OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.Show less
1Openstack
1Swift
May 6, 2026
Jan 29, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted request...Show more
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.Show less
4Fedoraproject
OpenstackOracle+1 more
4Fedora
OpenstackOrchestration Api+1 more
May 6, 2026
Jan 20, 2016
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine...Show more
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.Show less
1Openstack
1Nova
May 6, 2026
Jan 15, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen ba...Show more
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.Show less
2Fedoraproject
Openstack
2Fedora
Swift3
May 6, 2026
Jan 13, 2016
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
1Openstack
1Nova
May 6, 2026
Jan 12, 2016
N/A· v4
3.5 LOW· v3
2.1 LOW· v2
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by ov...Show more
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.Show less
1Openstack
1Ironic Inspector
May 6, 2026
Nov 25, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error.
1Openstack
1Nova
May 6, 2026
Oct 29, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance tha...Show more
OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made.Show less
1Openstack
1Neutron
May 6, 2026
Oct 27, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing...Show more
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.Show less
1Openstack
1Image Registry And Delivery Service (glance)
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting image...Show more
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9623.Show less
1Openstack
1Image Registry And Delivery Service (glance)
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
5.5 MEDIUM· v2
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-s...Show more
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.Show less
1Openstack
1Swift
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container.
1Openstack
1Nova
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consum...Show more
OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state.Show less
1Openstack
1Nova
May 6, 2026
Sep 8, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, networ...Show more
OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance.Show less