← Back

Openstack

openstack

277 CVEs • 65 products

Products (65)

Click to collapse
Toggle
Keystone
keystone
Nova
nova
Folsom
folsom
Neutron
neutron
Horizon
horizon
Essex
essex
Swift
swift
Grizzly
grizzly
Compute
compute
Glance
glance
Havana
havana
Cinder
cinder
Ironic
ironic
Heat
heat
Barbican
barbican
Icehouse
icehouse
Trove
trove
Diablo
diablo
Ceilometer
ceilometer
Oslo
oslo
Murano
murano
Manila
manila
Designate
designate
Octavia
octavia
Magnum
magnum
Cinder Folsom
cinder_folsom
Devstack
devstack
Pycadf
pycadf
Juno
juno
Kilo
kilo
Swift3
swift3
Mitaka Murano
mitaka-murano
Compute (nova)
compute_(nova)
Puppet Gerrit
puppet-gerrit
Nova Lxd
nova-lxd
Openstack
openstack
Swauth
swauth
Puppet Tripleo
puppet-tripleo
Puppet Swift
puppet-swift
Tripleo Common
tripleo-common
Os Vif
os-vif
Oslo.utils
oslo.utils
Kolla
kolla
Glance Store
glance-store
Yaql
yaql
Vitrage
vitrage

CVEs (277)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openstack
1Nova
Jun 17, 2026
Jul 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an...Show more
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Nova deployments are affected. NOTE: this issue exists because of an incomplete fix for CVE-2022-47951 and CVE-2024-32498.Show less
1Openstack
3Cinder
GlanceNova
Jun 17, 2026
Jul 5, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references...Show more
An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data. All Cinder and Nova deployments are affected; only Glance deployments with image conversion enabled are affected.Show less
1Openstack
1Magnum
Jun 17, 2026
Apr 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.
1Openstack
2Murano
Yaql
Jun 17, 2026
Mar 18, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive servi...Show more
In OpenStack Murano through 16.0.0, when YAQL before 3.0.0 is used, the Murano service's MuranoPL extension to the YAQL language fails to sanitize the supplied environment, leading to potential leakage of sensitive service account information.Show less
1Openstack
1Glance Store
Jun 17, 2026
Feb 1, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the DEBUG log level is enabled.
2Openstack
Redhat
2Barbican
Openstack Platform
Jun 17, 2026
Sep 24, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespac...Show more
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any service is compromised, it could gain access to the data transmitted to and from Barbican.Show less
2Openstack
Redhat
2Barbican
Openstack Platform
Jun 17, 2026
Sep 24, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A credentials leak flaw was found in OpenStack Barbican. This flaw allows a local authenticated attacker to read the configuration file, gaining access to sensitive credentials.
2Openstack
Redhat
2Heat
Openstack Platform
Jun 17, 2026
Sep 24, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impac...Show more
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.Show less
1Openstack
1Horizon
Jun 17, 2026
Aug 22, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.
2Openstack
Redhat
3Openstack
Openstack For Ibm PowerTripleo Ansible
Jun 17, 2026
Mar 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.Show less
2Openstack
Redhat
3Openstack
Openstack For Ibm PowerTripleo Ansible
Jun 17, 2026
Mar 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the rele...Show more
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.Show less
2Openstack
Redhat
2Glance
Openstack
Jun 17, 2026
Mar 6, 2023
N/A· v4
2.8 LOW· v3
N/A· v2
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
2Openstack
Redhat
2Neutron
Openstack Platform
Jun 17, 2026
Mar 6, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unco...Show more
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.Show less
2Debian
Openstack
4Cinder
Debian LinuxGlance+1 more
Jun 17, 2026
Jan 26, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a spec...Show more
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.Show less
2Debian
Openstack
2Debian Linux
Swift
Jun 17, 2026
Jan 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host...Show more
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).Show less
2Openstack
Redhat
4Barbican
OpenstackOpenstack For Ibm Power+1 more
Jun 17, 2026
Jan 18, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
1Openstack
1Kolla
Jun 17, 2026
Dec 21, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
2Openstack
Redhat
2Barbican
Openstack Platform
Jun 17, 2026
Sep 6, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This...Show more
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.Show less
2Openstack
Redhat
4Keystone
Openstack PlatformQuay+1 more
Jun 17, 2026
Sep 1, 2022
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote admini...Show more
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.Show less
2Openstack
Redhat
2Barbican
Openstack Platform
Jun 17, 2026
Sep 1, 2022
N/A· v4
4.9 MEDIUM· v3
N/A· v2
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and ca...Show more
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.Show less