CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Signature header. By sending a request with an empty URL-Signature header, an unauthenticat…
openstack-swift: openstack-swift: unauthorized read of other objects via TempURL and X-Copy-From
openstack-octavia: octavia: HAProxy configuration injection via tls_ciphers on pools and listeners
openstack-octavia: octavia: HAProxy configuration injection via L7 policy redirect_url and redirect_prefix
In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id}…
In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an adm…
openstack-glance: openstack-glance: SSRF via location API missing host validation
ironic: OpenStack Ironic: Information disclosure via unexpected credential transmission
An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OA…
keystone: OpenStack Keystone: Information disclosure via improper handling of domain IDs in role assignment listings
keystone: keystone: Application credential tokens can escape project scope via token-method reauthentication
keystone: keystone: Delegated token scope restrictions not consistently enforced across trust, OAuth1, and application credential endpoints
glance: OpenStack Glance: Server-Side Request Forgery allows internal URL access by administrators
aodh: python-watcher: aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization
ironic: OpenStack Ironic: Autodetect deploy interface fails to run cleaning
octavia: OpenStack Octavia: Authenticated user can prevent QoS policy deletion
openstack-designate: designate: mDNS NOTIFY handler DoS via pool-blind zone lookup
openstack-designate: designate: cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler
ironic: OpenStack Ironic: Information disclosure via crafted request
openstack-swift: openstack-swift: S3API cross-tenant object read via Swift-native header injection
openstack-swift: openstack-swift: S3API presigned URL unsigned header authorization bypass
openstack-swift: openstack-swift: Unauthenticated denial of service via catastrophic backtracking in Accept header parser
openstack-neutron: openstack-neutron: Shared-network consumer can re-scope another project's subnets via subnetpool onboarding
OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.
ironic-python-agent: OpenStack Ironic Python Agent: Arbitrary code execution via malicious configuration
Showing 1 to 25 CVEs · page 1 (more available)