OpenStack / Essex
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2013-1838 | Nova: DoS by allocating all Fixed IPs | HIGH | 7.1 | Mar 22, 2013 |
| CVE-2013-0335 | Openstack nova: vnc proxy can connect to the wrong vm | HIGH | 7.1 | Mar 22, 2013 |
| CVE-2013-0266 | Puppetlabs-cinder: packstack: openstack: puppetlabs-cinder: information disclosure of openstack administrative passwords due to world-readable configuration fi… | MEDIUM | 5.5 | Mar 8, 2013 |
| CVE-2013-0261 | Packstack: packstack: arbitrary file overwrite via symlink attack | HIGH | 8.8 | Mar 8, 2013 |
| CVE-2013-0208 | openstack-nova: Boot from volume allows access to random volumes | MEDIUM | 6.5 | Feb 13, 2013 |
| CVE-2012-5571 | Openstack keystone: openstack keystone: authorization bypass via improper ec2 token handling | MEDIUM | 5.4 | Dec 18, 2012 |
| CVE-2012-5482 | The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an i… | MEDIUM | 5.5 | Nov 11, 2012 |
| CVE-2012-4573 | OpenStack: Glance Authentication bypass for image deletion | MEDIUM | 5.5 | Nov 11, 2012 |
| CVE-2012-3542 | Keystone: Lack of authorization for adding users to tenants | HIGH | 8.7 | Sep 5, 2012 |
| CVE-2012-3426 | OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows… | MEDIUM | 4.9 | Jul 31, 2012 |
| CVE-2012-3361 | virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbitrary file… | MEDIUM | 5.5 | Jul 22, 2012 |
| CVE-2012-3360 | Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors,… | MEDIUM | 5.5 | Jul 22, 2012 |
| CVE-2012-3371 | The Nova scheduler in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when DifferentHostFilter or SameHostFilter is enabled, allows remote authent… | LOW | 3.5 | Jul 17, 2012 |
| CVE-2012-2654 | The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security g… | MEDIUM | 4.3 | Jun 21, 2012 |
| CVE-2012-0030 | Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI re… | MEDIUM | 4.9 | Jan 13, 2012 |
Showing 1 to 15 of 15 CVEs