Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Swift HIGH 7.5
CVE-2016-0738

OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows …

Fix: after 2.3.0
Fix from $1,950 2016-01-29
Swift HIGH 7.5
CVE-2016-0737

OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service …

Fix: after 2.3.0
Fix from $1,950 2016-01-29
Nova MEDIUM 5.9
CVE-2015-8749

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the conne…

Fix: 12.0.1 / 2015.1.3+
Fix from $1,600 2016-01-15
Ironic Inspector MEDIUM 6.8
CVE-2015-5306

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask c…

Mitigation only
Fix from $1,600 2015-11-25
Nova MEDIUM 5.0
CVE-2015-7713

OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote…

Fix: 2014.2.4 / 2015.1.2+
Fix from $1,600 2015-10-29
Image Registry And Delivery Service \(glance\) MEDIUM 6.8
CVE-2015-5286

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q…

Fix: after 2014.2.3
Fix from $1,600 2015-10-26
Image Registry And Delivery Service \(glance\) MEDIUM 5.5
CVE-2015-5251

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of …

Fix: after 2014.2.3
Fix from $1,600 2015-10-26
Swift MEDIUM 5.0
CVE-2015-5223

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that refer…

Fix: after 2.3.0
Fix from $1,600 2015-10-26
Nova MEDIUM 6.8
CVE-2015-3280

OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allo…

Fix: 2014.2.4 / 2015.1.2+
Fix from $1,600 2015-10-26
Nova MEDIUM 6.8
CVE-2015-3241

OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allow…

Fix: after 2015.1.1
Fix from $1,600 2015-09-08
Nova MEDIUM 5.1
CVE-2015-0259

OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which …

Fix: 2014.1.4 / 2014.2.3+
Fix from $1,600 2015-04-01
Image Registry And Delivery Service \(glance\) MEDIUM 6.5
CVE-2015-1195

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users t…

Fix: 2014.1.4 / 2014.2.2+
Fix from $1,600 2015-01-21
Keystone MEDIUM 6.5
CVE-2014-0204

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allow…

Fix: 2014.1.1+
Fix from $1,600 2014-11-03
Keystone MEDIUM 6.5
CVE-2014-3520

OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to …

Fix: 2013.2.4 / 2014.1.2+
Fix from $1,600 2014-10-26
Nova MEDIUM 6.5
CVE-2014-8750

Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to acce…

Fix: 2014.1.4+
Fix from $1,600 2014-10-15
Neutron HIGH 7.6
CVE-2014-3632

The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stac…

Fix: after 2014.1.2
Fix from $1,950 2014-10-07
Keystone MEDIUM 6.0
CVE-2014-3476

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allo…

Fix: 2013.2.4 / 2014.1.2+
Fix from $1,600 2014-06-17
Horizon MEDIUM 5.5
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w…

Fix: 2013.2+
Fix from $1,600 2014-05-14
Icehouse MEDIUM 6.0
CVE-2014-0162

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote …

Mitigation only
Fix from $1,600 2014-04-27
Keystone HIGH 7.8
CVE-2014-2828

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-04-15
Compute MEDIUM 6.0
CVE-2014-0167

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R…

Patch available
Fix from $1,600 2014-04-15
Python Keystoneclient MEDIUM 6.0
CVE-2014-0105

The auth_token middleware in the OpenStack Python client library for Keystone (aka python-keystoneclient) before 0.7.0 does not properly retrieve use…

Fix: after 0.4.2
Fix from $1,600 2014-04-15
Keystone MEDIUM 5.0
CVE-2014-2237

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i…

Mitigation only
Fix from $1,600 2014-04-01
Swift MEDIUM 5.8
CVE-2013-6396

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allow…

Mitigation only
Fix from $1,600 2014-02-18
Compute HIGH 7.1
CVE-2013-7130

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…

Patch available
Fix from $1,950 2014-02-06
Python Keystoneclient MEDIUM 5.5
CVE-2013-2104

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen…

Fix: after 0.2.3
Fix from $1,600 2014-01-21
Havana MEDIUM 5.0
CVE-2013-6419

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…

Patch available
Fix from $1,600 2014-01-07
Havana MEDIUM 6.4
CVE-2013-4497

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…

Mitigation only
Fix from $1,600 2013-11-05
Keystone MEDIUM 5.0
CVE-2013-4294

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the …

Patch available
Fix from $1,600 2013-09-23
Nova MEDIUM 6.0
CVE-2013-2256

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r…

Fix: 2013.1.3+
Fix from $1,600 2013-09-16