Openstack
openstack
266 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (266)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Openstack Redhat2Neutron Openstack PlatformNov 21, 2024 May 28, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses...Show more |
2Debian Openstack2Debian Linux HorizonNov 21, 2024 Dec 4, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply...Show more |
1Openstack 1Blazar Dashboard Nov 21, 2024 Oct 16, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon servic...Show more |
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration,...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxNov 21, 2024 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxNov 21, 2024 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to...Show more |
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keys...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxNov 21, 2024 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such...Show more |
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create r...Show more |
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens use...Show more |
2Debian Openstack2Debian Linux HorizonNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value. |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraHorizon+1 moreNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
3Debian OpenstackRedhat3Debian Linux OpenstackPython KeystoneclientNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraOpenstack+1 moreNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Us...Show more |
2Debian Openstack2Debian Linux NovaNov 21, 2024 Dec 5, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 OpenStack nova base images permissions are world readable |
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow ma...Show more |
3Debian OpenstackRedhat3Debian Linux DesignateEnterprise Linux Openstack PlatformNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Designate does not enforce the DNS protocol limit concerning record set sizes |
2Debian Openstack2Debian Linux KeystoneNov 21, 2024 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space |
3Debian OpenstackRedhat4Compute Debian LinuxKeystone+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. |