openstack
276 tracked vulnerabilities.
CVE-2014-3475
OpenStack Horizon < 2013.2.4, 2014.1 < 2014.1.2, Juno < Juno-2 - Cross-Site Scripting via User Email Address
Oct 31, 2014
EPSS 0.00
CVE-2014-3474
OpenStack Horizon <2013.2.4, 2014.1<2014.1.2, Juno<Juno-2 - Stored XSS via Network Name
Oct 31, 2014
EPSS 0.00
CVE-2014-3473
OpenStack Horizon < 2013.2.4, 2014.1 < 2014.1.2, Juno < Juno-2 - Cross-Site Scripting in Orchestration Template
Oct 31, 2014
EPSS 0.00
CVE-2014-8333
OpenStack Nova < 2014.1.4 - Authenticated Denial of Service via VMware Driver Instance Deletion
Oct 31, 2014
EPSS 0.01
CVE-2014-3708
OpenStack Nova < 2014.1.4, 2014.2.x < 2014.2.1 - DoS via IP Filter in List Active Servers API
Oct 31, 2014
EPSS 0.01
CVE-2014-3520
OpenStack Keystone < 2013.2.4 - Authenticated Incorrect Authorization via V2 API Trust Token Request
Oct 26, 2014
EPSS 0.00
CVE-2014-7960
OpenStack Swift < 2.2.0 - Authenticated Metadata Constraint Bypass via Multiple Requests
Oct 17, 2014
EPSS 0.00
CVE-2014-8750
OpenStack Compute (Nova) <2014.1.4, <2014.2-2014.2rc1 - Privilege E...
Oct 15, 2014
EPSS 0.01
CVE-2014-7231
OpenStack <2013.2.4 & <2014.1.3 - Info Disclosure
Oct 08, 2014
EPSS 0.00
CVE-2014-7230
OpenStack <2013.2.4 & <2014.1.3 - Info Disclosure
Oct 08, 2014
EPSS 0.00
CVE-2014-3641
OpenStack Cinder < 2014.1.3 - Authenticated Sensitive Information Exposure via Crafted qcow2 Header
Oct 08, 2014
EPSS 0.00
CVE-2014-3632
openstack neutron 2014.1-2014.1.2 - Remote Privilege Escalation via Sudoers Configuration
Oct 07, 2014
EPSS 0.01
CVE-2014-3608
OpenStack Nova < 2014.1.3 - Authenticated Denial of Service via VM Rescue State Bypass
Oct 06, 2014
EPSS 0.01
CVE-2014-7144
OpenStack keystonemiddleware <0.11.0-1.2.0 - Man-in-the-Middle
Oct 02, 2014
EPSS 0.01
CVE-2014-6414
OpenStack Neutron <2014.2.4-2014.1.2 - Privilege Escalation
Oct 02, 2014
EPSS 0.01
CVE-2014-3621
OpenStack Keystone <2013.2.3/2014.1<2014.1.2.1 Authenticated Sensitive Info Exposure
Oct 02, 2014
EPSS 0.00
CVE-2014-5356
OpenStack Glance < 2013.2.4, 2014.x < 2014.1.3, Juno < Juno-3 - Authenticated Denial of Service via V2 API Image Upload
Aug 25, 2014
EPSS 0.01
CVE-2014-5253
OpenStack Keystone 2014.1.x < 2014.1.2.1 and Juno < Juno-3 - Authenticated Token Persistence via Invalidated Domain
Aug 25, 2014
EPSS 0.00
CVE-2014-5252
OpenStack Keystone 2014.1.x < 2014.1.2.1 and Juno < Juno-3 - Authenticated Token Expiration Bypass via V3 API
Aug 25, 2014
EPSS 0.00
CVE-2014-5251
OpenStack Keystone < 2014.1.2.1 / Juno < Juno-3 Token Expiration Bypass
Aug 25, 2014
EPSS 0.00
CVE-2014-3594
OpenStack Horizon < 2013.2.4, 2014.1 < 2014.1.2, Juno < Juno-3 - Cross-Site Scripting via Host Aggregate Name
Aug 22, 2014
EPSS 0.01
CVE-2014-4615
OpenStack PyCADF <0.5.0, Telemetry <2013.2.4, Neutron <2014.1.2, Ju...
Aug 19, 2014
EPSS 0.01
CVE-2014-3517
OpenStack Nova < 2013.2.4 - Instance ID Signature Exposure via Metadata Request Timing
Aug 07, 2014
EPSS 0.00
CVE-2014-3555
OpenStack Neutron DoS via Allowed Address Pairs (2013.2.4, 2014.1.2, Juno-2)
Jul 23, 2014
EPSS 0.01
CVE-2014-4167
OpenStack Neutron <2013.2.4, 2014.x <2014.1.2, Juno-2 - DoS
Jul 11, 2014
EPSS 0.01
Products
keystone 39
nova 38
folsom 25
neutron 25
horizon 22
essex 15
image_registry_and_delivery_service_\(glance\) 15
grizzly 14
swift 13
compute 12
glance 12
havana 11
cinder 9
heat 7
python-keystoneclient 7
Ironic 5
barbican 5
tripleo_heat_templates 5
Keystone 4
icehouse 4
keystonemiddleware 3
trove 3
Cyborg 2
ceilometer 2
cloud_magnum_orchestration 2
designate 2
diablo 2
keystone_essex 2
magnum 2
manila 2
Quick Filters