VYPR

Vendor CVEs

OpenStack

All CVEs

348 total · sorted by risk
  • CVE-2023-1625HigSep 24, 2023
    risk 0.41cvss 7.4epss 0.01

    An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of…

  • CVE-2017-12155MedDec 12, 2017
    risk 0.41cvss 6.3epss 0.00

    A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenStack as though the attacker…

  • CVE-2022-45582MedAug 22, 2023
    risk 0.40cvss 6.1epss 0.01

    Open Redirect vulnerability in Horizon Web Dashboard 19.4.0 thru 20.1.4 via the success_url parameter.

  • CVE-2016-5737MedJan 12, 2017
    risk 0.40cvss 6.1epss 0.02

    The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.

  • CVE-2026-71192MedAug 5, 2026
    risk 0.39cvss —epss 0.00

    In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API requests when s3_acl=true. An attacker can inject these headers into a signed PUT request targeting their own bucket, causing…

  • CVE-2026-71191MedAug 5, 2026
    risk 0.39cvss —epss 0.00

    In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned URL requests. An attacker who obtains a presigned PUT URL can inject an unsigned X-Amz-Copy-Source header, causing Swift to perform…

  • CVE-2026-55748MedJun 17, 2026
    risk 0.39cvss 6.0epss 0.00

    OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.

  • CVE-2023-1636MedSep 24, 2023
    risk 0.39cvss 6.0epss 0.00

    A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host system and other OpenStack services. If any…

  • CVE-2026-48681MedJun 4, 2026
    risk 0.38cvss 5.9epss 0.01

    OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.

  • CVE-2022-3100MedJan 18, 2023
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.

  • CVE-2017-2622MedJul 27, 2018
    risk 0.38cvss 5.9epss 0.00

    An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

  • CVE-2017-2592MedMay 8, 2018
    risk 0.38cvss 5.9epss 0.00

    python-oslo-middleware before versions 3.8.1, 3.19.1, 3.23.1 is vulnerable to an information disclosure. Software using the CatchError class could include sensitive values in a traceback's error message. System users could exploit this flaw to obtain sensitive information from…

  • CVE-2026-71194MedAug 12, 2026
    risk 0.37cvss 6.8epss 0.00

    In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return…

  • CVE-2026-54421MedJun 14, 2026
    risk 0.37cvss 6.8epss 0.00

    In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security…

  • CVE-2022-47951MedJan 26, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific…

  • CVE-2026-44918MedJul 10, 2026
    risk 0.36cvss 5.5epss 0.00

    OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.

  • CVE-2026-42510MedApr 28, 2026
    risk 0.36cvss 6.6epss 0.01

    OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.

  • CVE-2024-4840MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    An flaw was found in the OpenStack Platform (RHOSP) director, a toolset for installing and managing a complete RHOSP environment. Plaintext passwords may be stored in log files, which can expose sensitive information to anyone with access to the logs.

  • CVE-2023-6725MedMar 15, 2024
    risk 0.36cvss 5.5epss 0.00

    An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive…

  • CVE-2022-3146MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to…

  • CVE-2022-3101MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to…

  • CVE-2022-44020MedOct 30, 2022
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like…

  • CVE-2021-3585MedAug 26, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

  • CVE-2012-5476MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.

  • CVE-2012-5474MedDec 30, 2019
    risk 0.36cvss 5.5epss 0.00

    The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.

  • CVE-2013-0326MedDec 5, 2019
    risk 0.36cvss 5.5epss 0.00

    OpenStack nova base images permissions are world readable

  • CVE-2019-3866MedNov 8, 2019
    risk 0.36cvss 5.5epss 0.00

    An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

  • CVE-2019-9735MedMar 13, 2019
    risk 0.36cvss 6.5epss 0.03

    An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example,…

  • CVE-2017-2621MedJul 27, 2018
    risk 0.36cvss 5.5epss 0.00

    An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

  • CVE-2015-8234MedMar 29, 2017
    risk 0.36cvss 5.5epss 0.02

    The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

  • CVE-2013-0270MedApr 12, 2013
    risk 0.36cvss 6.5epss 0.03

    A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources…

  • CVE-2026-46448MedJun 16, 2026
    risk 0.35cvss 5.4epss 0.00

    In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

  • CVE-2026-40212MedApr 10, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

  • CVE-2024-32498MedJul 5, 2024
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an authenticated user may…

  • CVE-2022-3277MedMar 6, 2023
    risk 0.35cvss 6.5epss 0.01

    An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to…

  • CVE-2022-47950MedJan 18, 2023
    risk 0.35cvss 6.5epss 0.01

    An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to…

  • CVE-2021-40797MedSep 8, 2021
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. By making API requests involving nonexistent controllers, an authenticated user may cause the API worker to consume increasing amounts of memory,…

  • CVE-2021-40085MedAug 31, 2021
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated attackers can reconfigure dnsmasq via a crafted extra_dhcp_opts value.

  • CVE-2018-16848MedJun 15, 2020
    risk 0.35cvss 6.5epss 0.01

    A Denial of Service (DoS) condition is possible in OpenStack Mistral in versions up to and including 7.0.3. Submitting a specially crafted workflow definition YAML file containing nested anchors can lead to resource exhaustion culminating in a denial of service.

  • CVE-2020-12692MedMay 7, 2020
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The EC2 API doesn't have a signature TTL check for AWS Signature V4. An attacker can sniff the Authorization header, and then use it to reissue an OpenStack token an unlimited number of times.

  • CVE-2019-14433MedAug 9, 2019
    risk 0.35cvss 6.5epss 0.02

    An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and…

  • CVE-2018-20170MedDec 17, 2018
    risk 0.35cvss 5.3epss 0.01

    OpenStack Keystone through 14.0.1 has a user enumeration vulnerability because invalid usernames have much faster responses than valid ones for a POST /v3/auth/tokens request. NOTE: the vendor's position is that this is a hardening opportunity, and not necessarily an issue that…

  • CVE-2018-14636MedSep 10, 2018
    risk 0.35cvss 5.3epss 0.01

    Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete.…

  • CVE-2018-14635MedSep 10, 2018
    risk 0.35cvss 6.5epss 0.03

    When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then…

  • CVE-2017-7543MedJul 26, 2018
    risk 0.35cvss 5.3epss 0.02

    A race-condition flaw was discovered in openstack-neutron before 7.2.0-12.1, 8.x before 8.3.0-11.1, 9.x before 9.3.1-2.1, and 10.x before 10.0.2-1.1, where, following a minor overcloud update, neutron security groups were disabled. Specifically, the following were reset to 0:…

  • CVE-2016-9590MedApr 26, 2018
    risk 0.35cvss 6.5epss 0.01

    puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates…

  • CVE-2017-16239MedNov 14, 2017
    risk 0.35cvss 6.5epss 0.01

    In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter). All…

  • CVE-2016-2102MedAug 22, 2017
    risk 0.35cvss 5.3epss 0.02

    HAProxy statistics in openstack-tripleo-image-elements are non-authenticated over the network.

  • CVE-2026-50589MedJun 5, 2026
    risk 0.34cvss 5.3epss 0.00

    In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

  • CVE-2026-49299MedMay 28, 2026
    risk 0.34cvss —epss 0.00

    In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names evaluate as allowed under the default policy, permitting a project reader to…

Page 3 of 7