Vulnerabilities > Openstack > Compute > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-01 CVE-2013-2255 Improper Certificate Validation vulnerability in multiple products
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
4.3
2013-10-29 CVE-2013-4185 Cryptographic Issues vulnerability in multiple products
Algorithmic complexity vulnerability in OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-3 does not properly handle network source security group policy updates, which allows remote authenticated users to cause a denial of service (nova-network consumption) via a large number of server-creation operations, which triggers a large number of update requests.
network
low complexity
openstack redhat CWE-310
4.0
2012-06-21 CVE-2012-2654 Improper Input Validation vulnerability in Openstack Compute, Diablo and Essex
The (1) EC2 and (2) OS APIs in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) do not properly check the protocol when security groups are created and the network protocol is not specified entirely in lowercase, which allows remote attackers to bypass intended access restrictions.
network
openstack CWE-20
4.3