Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Python Glanceclient MEDIUM 5.8
CVE-2013-4111

The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server ho…

Mitigation only
Fix from $1,600 2013-08-28
Folsom HIGH 7.5
CVE-2013-2161

XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…

Mitigation only
Fix from $1,950 2013-08-20
Keystone MEDIUM 6.0
CVE-2013-2059

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token w…

No fix yet
Fix from $1,600 2013-05-21
Keystone MEDIUM 6.5
CVE-2013-0270

A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing…

Fix: after 2012.2.4
Fix from $1,600 2013-04-12
Keystone MEDIUM 5.0
CVE-2013-0282

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain i…

Fix: after 2012.2.4
Fix from $1,600 2013-04-12
Cinder Folsom MEDIUM 5.0
CVE-2013-1664

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Fol…

No fix yet
Fix from $1,600 2013-04-03
Folsom MEDIUM 5.0
CVE-2013-1665

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products al…

Patch available
Fix from $1,600 2013-04-03
Essex HIGH 8.8
CVE-2013-0261

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …

Mitigation only
Fix from $1,950 2013-03-08
Essex MEDIUM 5.5
CVE-2013-0266

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world…

Patch available
Fix from $1,600 2013-03-08
Essex MEDIUM 5.4
CVE-2012-5571

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occu…

Patch available
Fix from $1,600 2012-12-18
Essex MEDIUM 5.5
CVE-2012-5482

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…

Patch available
Fix from $1,600 2012-11-11
Essex MEDIUM 5.5
CVE-2012-4573

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…

Patch available
Fix from $1,600 2012-11-11
Keystone HIGH 7.5
CVE-2012-4456

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-…

Fix: 2012.1.2+
Fix from $1,950 2012-10-09
Horizon MEDIUM 5.8
CVE-2012-3540

Open redirect vulnerability in views/auth_forms.py in OpenStack Dashboard (Horizon) Essex (2012.1) allows remote attackers to redirect users to arbit…

Patch available
Fix from $1,600 2012-09-05
Diablo MEDIUM 5.5
CVE-2012-3361

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbi…

Patch available
Fix from $1,600 2012-07-22
Essex MEDIUM 5.5
CVE-2012-3360

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hy…

Patch available
Fix from $1,600 2012-07-22
Horizon MEDIUM 6.8
CVE-2012-2144

Session fixation vulnerability in OpenStack Dashboard (Horizon) folsom-1 and 2012.1 allows remote attackers to hijack web sessions via the sessionid …

Patch available
Fix from $1,600 2012-06-05
Nova MEDIUM 6.0
CVE-2011-4596

Multiple directory traversal vulnerabilities in OpenStack Nova before 2011.3.1, when the EC2 API and the S3/RegisterImage image-registration method a…

Fix: 2011.3.1+
Fix from $1,600 2011-12-23