Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2020-12690 An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles provided for an OAuth1 access token is silently ignored. T… Keystone 15.0.1+ Fix from $1,9502020-05-07 HIGH 8.3 CVE-2020-9543 OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, … Manila 7.4.1 / 8.1.1+ Fix from $1,9502020-03-12 HIGH 8.8 CVE-2019-19687 OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any c… Keystone Patch available Fix from $1,9502019-12-09 MEDIUM 5.9 CVE-2011-4076 OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a… Nova 2012.1+ Fix from $1,6002019-11-26 CRITICAL 9.1 CVE-2019-15753 In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatory Ether… Os Vif 1.15.2+ Fix from $2,3002019-08-28 CRITICAL 9.8 CVE-2016-7404 OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be used for retrieving the inst… Magnum Patch available Fix from $2,3002019-06-21 HIGH 8.6 CVE-2011-3147 Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesyst… Nova 2012.1+ Fix from $1,9502019-04-22 MEDIUM 5.3 CVE-2018-20170 OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POS… Keystone after 14.0.1 Fix from $1,6002018-12-17 MEDIUM 5.3 CVE-2018-14636 Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinit… Neutron after 12.0.2 Fix from $1,6002018-09-10 MEDIUM 6.5 CVE-2016-8611 A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method fo… Glance Mitigation only Fix from $1,6002018-07-31 HIGH 8.6 CVE-2017-17051 An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticat… Nova Mitigation only Fix from $1,9502017-12-05 MEDIUM 6.5 CVE-2017-16239 In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circu… Nova after 14.0.9 Fix from $1,6002017-11-14 MEDIUM 6.4 CVE-2017-7549 A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5… Instack Undercloud Mitigation only Fix from $1,6002017-09-21 MEDIUM 6.5 CVE-2015-5695 Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when proc… Designate Patch available Fix from $1,6002017-08-31 HIGH 7.5 CVE-2017-12440 Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that tr… Openstack Patch available Fix from $1,9502017-08-18 MEDIUM 5.5 CVE-2015-3156 The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/… Trove after 2014.2.4 Fix from $1,6002017-08-11 MEDIUM 6.5 CVE-2015-7514 OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information. Ironic Patch available Fix from $1,6002017-06-07 MEDIUM 5.5 CVE-2015-8234 The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, wh… Glance Patch available Fix from $1,6002017-03-29 CRITICAL 9.8 CVE-2017-7214 An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notificat… Nova Patch available Fix from $2,3002017-03-21 MEDIUM 5.8 CVE-2017-7200 An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform ma… Glance Mitigation only Fix from $1,6002017-03-21 MEDIUM 6.1 CVE-2016-5737 The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might all… Puppet Gerrit Patch available Fix from $1,6002017-01-12 HIGH 7.5 CVE-2015-5162 The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not prope… Cinder after 12.0.3 Fix from $1,9502016-10-07 MEDIUM 6.5 CVE-2016-7498 OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of s… Compute \(nova\) Patch available Fix from $1,6002016-09-27 CRITICAL 9.8 CVE-2016-4972 OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and pyt… Mitaka Murano after 2.0.0 Fix from $2,3002016-09-26 HIGH 8.2 CVE-2016-5363 The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection… Neutron Mitigation only Fix from $1,9502016-06-17 HIGH 8.2 CVE-2016-5362 The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protectio… Neutron 7.0.4+ Fix from $1,9502016-06-17 CRITICAL 9.1 CVE-2015-8914 The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protect… Neutron 7.0.4+ Fix from $2,3002016-06-17 MEDIUM 5.3 CVE-2016-2140 The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images i… Nova 12.0.3 / 2015.1.4+ Fix from $1,6002016-04-12 HIGH 7.5 CVE-2015-5303 The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networkin… Tripleo Heat Templates Mitigation only Fix from $1,9502016-04-11 HIGH 7.5 CVE-2015-7546 The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python… Keystonemiddleware 8.0.2+ Fix from $1,9502016-02-03