Vulnerabilities > Openstack

DATE CVE VULNERABILITY TITLE RISK
2020-12-04 CVE-2020-29565 Open Redirect vulnerability in Openstack Horizon 18.5.0
An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x.
network
openstack CWE-601
5.8
2020-10-16 CVE-2020-26943 Unspecified vulnerability in Openstack Blazar-Dashboard 2.0.0/3.0.0
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.
network
low complexity
openstack
critical
9.0
2020-08-26 CVE-2020-17376 XXE vulnerability in Openstack Nova
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0.
network
low complexity
openstack CWE-611
6.5
2020-05-07 CVE-2020-12692 Missing Encryption of Sensitive Data vulnerability in Openstack Keystone
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
network
low complexity
openstack CWE-311
5.5
2020-05-07 CVE-2020-12691 Missing Encryption of Sensitive Data vulnerability in Openstack Keystone
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
network
low complexity
openstack CWE-311
6.5
2020-05-07 CVE-2020-12690 Insufficient Session Expiration vulnerability in Openstack Keystone
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
network
low complexity
openstack CWE-613
6.5
2020-05-07 CVE-2020-12689 Improper Privilege Management vulnerability in Openstack Keystone
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
network
low complexity
openstack CWE-269
6.5
2020-03-12 CVE-2020-9543 Incorrect Default Permissions vulnerability in Openstack Manila
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID.
network
low complexity
openstack CWE-276
6.5
2020-02-20 CVE-2013-7109 Improper Input Validation vulnerability in Openstack Swift
OpenStack Swift as of 2013-12-15 mishandles PYTHON_EGG_CACHE
4.4
2020-02-19 CVE-2015-9543 Information Exposure vulnerability in Openstack Nova
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0.
local
low complexity
openstack CWE-200
2.1