Openstack
openstack
277 CVEs • 65 products
Products (65)
Click to collapseToggle
Products (65)
Click to collapse
CVEs (277)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens use...Show more |
2Debian Openstack2Debian Linux HorizonNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value. |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraHorizon+1 moreNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
3Debian OpenstackRedhat3Debian Linux OpenstackPython KeystoneclientNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraOpenstack+1 moreNov 21, 2024 Dec 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass |
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Us...Show more |
2Debian Openstack2Debian Linux NovaNov 21, 2024 Dec 5, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 OpenStack nova base images permissions are world readable |
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow ma...Show more |
3Debian OpenstackRedhat3Debian Linux DesignateEnterprise Linux Openstack PlatformNov 21, 2024 Nov 22, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Designate does not enforce the DNS protocol limit concerning record set sizes |
2Debian Openstack2Debian Linux KeystoneNov 21, 2024 Nov 12, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space |
3Debian OpenstackRedhat4Compute Debian LinuxKeystone+1 moreNov 21, 2024 Nov 1, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates. |
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ethernet flooding of non-local destinations, which both impedes network perf...Show more |
4Canonical DebianOpenstack+1 more4Debian Linux NovaOpenstack+1 moreJun 17, 2026 Aug 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the un...Show more |
2Openstack Redhat2Ironic Inspector OpenstackJun 17, 2026 Jul 30, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1. A SQL-injection vulnerability was found in openstack-ironic-inspector's node_cache.find_node(). This fu...Show more |
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the instances' SSL certificates, they allow full API access, though and can be...Show more |
2Openstack Redhat2Octavia OpenstackJun 17, 2026 Jun 3, 2019 N/A· v4 8.0 HIGH· v3 6.8 MEDIUM· v2 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant...Show more |
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem. |
2Openstack Redhat2Neutron OpenstackJun 17, 2026 Apr 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutro...Show more |
2Openstack Redhat2Ceilometer OpenstackJun 17, 2026 Mar 26, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated. |
2Openstack Redhat2Octavia OpenstackNov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Se...Show more |