Openstack
openstack
277 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (277)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OpenstackRedhat4Debian Linux Openshift Container PlatformOpenstack Platform+1 moreJun 17, 2026 Aug 29, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext. |
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager. |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstack PlatformJun 17, 2026 Aug 26, 2022 N/A· v4 7.4 HIGH· v3 N/A· v2 A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing attackers bypass some password complexity which administrators may be counting on. The highest threat fr...Show more |
An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vn...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesJun 17, 2026 Mar 23, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is vi...Show more |
2Openstack Redhat2Nova Openstack PlatformJun 17, 2026 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL. |
An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause t...Show more |
2Debian Openstack2Debian Linux NeutronJun 17, 2026 Aug 31, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value. |
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtables-nft is used on a Netfilter-based platform. By sending carefully crafted pack...Show more |
OpenStack Keystone 10.x through 16.x before 16.0.2, 17.x before 17.0.1, 18.x before 18.0.1, and 19.x before 19.0.1 allows information disclosure during account locking (related to PCI DSS features). By guessing the name...Show more |
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs. All Swift deployme...Show more |
2Openstack Redhat2Neutron Openstack PlatformJun 17, 2026 May 28, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyone in control of a server instance connected to the virtual switch can impersonate the IPv6 addresses...Show more |
2Debian Openstack2Debian Linux HorizonJun 17, 2026 Dec 4, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply...Show more |
1Openstack 1Blazar Dashboard Jun 17, 2026 Oct 16, 2020 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon servic...Show more |
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration,...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any authenticated user can create an EC2 credential for themselves for a project that they have a specified role on, and then perform an update to...Show more |
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. Thus, when an access token is used to request a keystone token, the keys...Show more |
2Canonical Openstack2Keystone Ubuntu LinuxJun 17, 2026 May 7, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such...Show more |
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create r...Show more |