Openstack
openstack
266 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (266)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network perf...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreNov 21, 2024 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
2Openstack Redhat2Ironic Inspector OpenstackNov 21, 2024 Jul 30, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This fu...Show more |
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be...Show more |
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Jun 3, 2019 N/A· v4 8.0 HIGH· v3 6.8 MEDIUM· v2 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant...Show more |
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem. |
2Openstack Redhat2Neutron OpenstackNov 21, 2024 Apr 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutro...Show more |
2Openstack Redhat2Ceilometer OpenstackNov 21, 2024 Mar 26, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated. |
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Se...Show more |
3Debian OpenstackRedhat3Debian Linux NeutronOpenstackNov 21, 2024 Mar 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along wit...Show more |
OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is...Show more |
Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-m...Show more |
2Openstack Redhat2Neutron OpenstackNov 21, 2024 Sep 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP add...Show more |
2Openstack Redhat2Cinder OpenstackNov 21, 2024 Aug 27, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes...Show more |
2Openstack Redhat2Openstack Tripleo CommonNov 21, 2024 Aug 22, 2018 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11. The sudoers file as installed with OSP's openstack-tripleo-common package is much too permissive. It contains several l...Show more |
A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method for authenticated users, resulting in possible denial of service attacks...Show more |
3Debian OpenstackRedhat3Debian Linux KeystoneOpenstackNov 21, 2024 Jul 31, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated...Show more |
2Openstack Redhat2Openstack Tripleo Heat TemplatesNov 21, 2024 Jul 30, 2018 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credent...Show more |
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this fl...Show more |
2Openstack Redhat2Neutron OpenstackNov 21, 2024 Jul 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups wer...Show more |