Search

Found 32 results in 105ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-44394 high 8.1 8.1 FIX debian debian openstack 6d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federate…
CVE-2026-43000 high 8.8 8.8 FIX debian debian openstack 6d ago An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…
CVE-2026-42999 high 8.8 8.8 FIX debian debian openstack 6d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …
CVE-2026-42998 high 8.8 8.8 FIX debian debian openstack 6d ago An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the…
CVE-2026-43003 high 7.5 7.5 debian debian openstack 1mo ago OpenStack Ironic Python Agent Includes Functionality from Untrusted Control Sphere
CVE-2026-43001 high 8.0 8.0 FIX debian debian openstack 1mo ago An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authentica…
CVE-2014-2828 high 7.8 FIX debian debian openstack 4y ago The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of service (CPU consumption) via a large number of the sa…
CVE-2015-8914 critical 9.1 9.1 FIX slesdebian debian openstack 4y ago The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of s…
CVE-2017-5936 high 7.5 7.5 ubuntu ubuntu openstack 4y ago OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restriction…
CVE-2017-17051 high 8.6 8.6 FIX debian debian openstack 9y ago An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hyper…
CVE-2017-16613 critical 9.8 9.8 debian debian openstack 9y ago An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and proxy server are saving (unhashed) tokens retrieve…
CVE-2017-12440 high 7.5 7.5 FIX debian debian sles openstack 9y ago Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm act…
CVE-2017-1000366 high 7.8 8.8 EXPFIX slesarch archdebian debian openstackgnumcafee 9y ago glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note…
CVE-2017-7214 critical 9.8 9.8 FIX slesdebian debian openstack 9y ago An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level lo…
CVE-2015-5162 high 7.5 7.5 FIX slesdebian debian openstack 10y ago The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attack…
CVE-2016-4972 critical 9.8 9.8 FIX debian debian openstack 10y ago OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x …
CVE-2016-5363 high 8.2 8.2 FIX slesdebian debian openstack 10y ago The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of serv…
CVE-2016-5362 high 8.2 8.2 FIX slesdebian debian openstack 10y ago The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of ser…
CVE-2015-5271 high 7.5 7.5 redhatopenstack 10y ago The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline w…
CVE-2015-5303 high 7.5 7.5 openstack 10y ago The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the…
CVE-2015-7546 high 7.5 7.5 FIX slesdebian debian openstack 11y ago The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty b…
CVE-2016-0738 high 7.5 7.5 FIX debian debian openstack 11y ago OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (pro…
CVE-2016-0737 high 7.5 7.5 FIX debian debian openstack 11y ago OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series o…
CVE-2015-8466 high 7.4 7.4 slesfedora fedora openstack 11y ago Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.
CVE-2014-3632 high 7.6 FIX debian debian openstack 12y ago The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stack Platform 5.0 for Red Hat Enterprise Linux 6, all…
CVE-2013-6433 high 7.6 FIX debian debianubuntu ubuntu openstack 12y ago The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which allows remote attackers to gain privileges via a cr…
CVE-2014-0187 critical 9.0 FIX debian debianubuntu ubuntususe suse openstack 12y ago The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass security group restrictions via an invalid CIDR in a s…
CVE-2013-7130 high 7.1 FIX debian debian openstack 13y ago The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not prope…
CVE-2013-2161 high 7.5 FIX suse susedebian debian openstack 13y ago XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.
CVE-2013-0261 high 8.8 8.8 openstack 13y ago A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite a…
CVE-2012-4406 critical 9.8 9.8 FIX fedora fedora rheldebian debian openstackredhat 14y ago OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arb…
CVE-2012-4456 high 7.5 FIX debian debian openstack 14y ago The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-Token, which allow remote attackers to read the ro…