← Back

Openstack

openstack

266 CVEs • 65 products

Products (65)

Click to collapse
Toggle
Keystone
keystone
Nova
nova
Folsom
folsom
Neutron
neutron
Horizon
horizon
Essex
essex
Grizzly
grizzly
Swift
swift
Compute
compute
Glance
glance
Havana
havana
Cinder
cinder
Heat
heat
Barbican
barbican
Icehouse
icehouse
Trove
trove
Diablo
diablo
Ceilometer
ceilometer
Oslo
oslo
Murano
murano
Manila
manila
Designate
designate
Octavia
octavia
Magnum
magnum
Cinder Folsom
cinder_folsom
Devstack
devstack
Pycadf
pycadf
Juno
juno
Kilo
kilo
Swift3
swift3
Mitaka Murano
mitaka-murano
Compute (nova)
compute_(nova)
Puppet Gerrit
puppet-gerrit
Nova Lxd
nova-lxd
Ironic
ironic
Openstack
openstack
Swauth
swauth
Puppet Tripleo
puppet-tripleo
Puppet Swift
puppet-swift
Tripleo Common
tripleo-common
Os Vif
os-vif
Oslo.utils
oslo.utils
Kolla
kolla
Glance Store
glance-store
Yaql
yaql
Vitrage
vitrage

CVEs (266)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openstack
1Neutron
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
7.6 HIGH· v2
The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers...Show more
The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, allows remote attackers to gain privileges via a crafted configuration file. NOTE: this vulnerability exists because of a CVE-2013-6433 regression.Show less
1Openstack
1Nova
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
2.7 LOW· v2
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, susp...Show more
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.Show less
1Openstack
2Keystonemiddleware
Python Keystoneclient
May 6, 2026
Oct 2, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardl...Show more
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.Show less
2Canonical
Openstack
2Neutron
Ubuntu Linux
May 6, 2026
Oct 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
3Canonical
OpenstackRedhat
3Keystone
OpenstackUbuntu Linux
May 6, 2026
Oct 2, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated...Show more
The catalog url replacement in OpenStack Identity (Keystone) before 2013.2.3 and 2014.1 before 2014.1.2.1 allows remote authenticated users to read sensitive configuration options via a crafted endpoint, as demonstrated by "$(admin_token)" in the publicurl endpoint field.Show less
2Canonical
Openstack
2Image Registry And Delivery Service (glance)
Ubuntu Linux
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allo...Show more
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.Show less
2Canonical
Openstack
2Keystone
Ubuntu Linux
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped t...Show more
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.Show less
2Canonical
Openstack
2Keystone
Ubuntu Linux
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and ret...Show more
The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated users to bypass the token expiration and retain access via a verification (1) GET or (2) HEAD request to v3/auth/tokens/.Show less
2Canonical
Openstack
2Keystone
Ubuntu Linux
May 6, 2026
Aug 25, 2014
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allo...Show more
The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expiration comparison for tokens to fail and allows remote authenticated users to retain access via an expired token.Show less
2Openstack
Opensuse
2Horizon
Opensuse
May 6, 2026
Aug 22, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary...Show more
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.Show less
3Canonical
OpenstackRedhat
6Neutron
OpenstackOslo+3 more
May 6, 2026
Aug 19, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authe...Show more
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).Show less
1Openstack
1Nova
May 6, 2026
Aug 7, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance...Show more
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.Show less
1Openstack
1Neutron
May 6, 2026
Jul 23, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed...Show more
OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (crash or long firewall rule updates) by creating a large number of allowed address pairs.Show less
2Canonical
Openstack
2Neutron
Ubuntu Linux
May 6, 2026
Jul 11, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 priva...Show more
The L3-agent in OpenStack Neutron before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to cause a denial of service (IPv4 address attachment outage) by attaching an IPv6 private subnet to a L3 router.Show less
1Openstack
1Swift
May 6, 2026
Jul 3, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in OpenStack Swift 1.11.0 through 1.13.1 allows remote attackers to inject arbitrary web script or HTML via the WWW-Authenticate header.
2Openstack
Suse
2Cloud
Keystone
May 6, 2026
Jun 17, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) tr...Show more
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) trust or (2) OAuth token with impersonation enabled to create a new token with additional roles.Show less
2Canonical
Openstack
2Neutron
Ubuntu Linux
May 6, 2026
Jun 2, 2014
N/A· v4
N/A· v3
7.6 HIGH· v2
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration f...Show more
The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a crafted configuration file.Show less
2Fedoraproject
Openstack
2Fedora
Keystone
May 6, 2026
Jun 2, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
1Openstack
1Heat
May 6, 2026
May 23, 2014
N/A· v4
N/A· v3
3.5 LOW· v2
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resou...Show more
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.Show less
1Openstack
1Horizon
May 6, 2026
May 14, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by...Show more
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user.Show less