Vulnerability index

Browse CVEs

18 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Kolla HIGH 8.8
CVE-2022-38060

A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers wi…

Mitigation only
Fix from $1,950 2022-12-21
Glance MEDIUM 6.5
CVE-2016-8611

A vulnerability was found in Openstack Glance. No limits are enforced within the Glance image service for both v1 and v2 `/images` API POST method fo…

Mitigation only
Fix from $1,600 2018-07-31
Nova HIGH 8.6
CVE-2017-17051

An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticat…

Mitigation only
Fix from $1,950 2017-12-05
Instack Undercloud MEDIUM 6.4
CVE-2017-7549

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5…

Mitigation only
Fix from $1,600 2017-09-21
Glance MEDIUM 5.8
CVE-2017-7200

An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform ma…

Mitigation only
Fix from $1,600 2017-03-21
Neutron HIGH 8.2
CVE-2016-5363

The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection…

Mitigation only
Fix from $1,950 2016-06-17
Tripleo Heat Templates HIGH 7.5
CVE-2015-5303

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networkin…

Mitigation only
Fix from $1,950 2016-04-11
Ironic Inspector MEDIUM 6.8
CVE-2015-5306

OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask c…

Mitigation only
Fix from $1,600 2015-11-25
Icehouse MEDIUM 6.0
CVE-2014-0162

The Sheepdog backend in OpenStack Image Registry and Delivery Service (Glance) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote …

Mitigation only
Fix from $1,600 2014-04-27
Keystone HIGH 7.8
CVE-2014-2828

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-04-15
Keystone MEDIUM 5.0
CVE-2014-2237

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i…

Mitigation only
Fix from $1,600 2014-04-01
Swift MEDIUM 5.8
CVE-2013-6396

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allow…

Mitigation only
Fix from $1,600 2014-02-18
Havana MEDIUM 6.4
CVE-2013-4497

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…

Mitigation only
Fix from $1,600 2013-11-05
Python Glanceclient MEDIUM 5.8
CVE-2013-4111

The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server ho…

Mitigation only
Fix from $1,600 2013-08-28
Folsom HIGH 7.5
CVE-2013-2161

XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift r…

Mitigation only
Fix from $1,950 2013-08-20
Keystone MEDIUM 6.0
CVE-2013-2059

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token w…

No fix yet
Fix from $1,600 2013-05-21
Cinder Folsom MEDIUM 5.0
CVE-2013-1664

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Fol…

No fix yet
Fix from $1,600 2013-04-03
Essex HIGH 8.8
CVE-2013-0261

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …

Mitigation only
Fix from $1,950 2013-03-08