VYPR

blazar-dashboard

by OpenStack

CVEs (2)

  • CVE-2020-26943CriOct 16, 2020
    risk 0.65cvss 9.9epss 0.03

    An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used).…

  • CVE-2012-5476MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.