VYPR

Openstack

by OpenStack

CVEs (9)

  • CVE-2016-6829CriDec 9, 2016
    risk 0.64cvss 9.8epss 0.02

    The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

  • CVE-2022-38065HigDec 21, 2022
    risk 0.57cvss 8.8epss 0.01

    A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

  • CVE-2022-38060HigDec 21, 2022
    risk 0.50cvss 8.8epss 0.00

    A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.

  • CVE-2013-1793HigDec 10, 2019
    risk 0.49cvss 7.5epss 0.01

    openstack-utils openstack-db has insecure password creation

  • CVE-2026-55707HigAug 5, 2026
    risk 0.46cvss —epss 0.00

    In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3…

  • CVE-2023-2088MedMay 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in OpenStack due to an inconsistency between Cinder and Nova. This issue can be triggered intentionally or by accident. A remote, authenticated attacker could exploit this vulnerability by detaching one of their volumes from Cinder. The highest impact is to…

  • CVE-2020-1690MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.00

    An improper authorization flaw was discovered in openstack-selinux's applied policy where it does not prevent a non-root user in a container from privilege escalation. A non-root attacker in one or more Red Hat OpenStack (RHOSP) containers could send messages to the dbus. With…

  • CVE-2017-12440HigAug 18, 2017
    risk 0.42cvss 7.5epss 0.02

    Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allows remote authenticated users with…

  • CVE-2022-3261MedSep 15, 2023
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.