Vulnerabilities > Openstack > Nova

DATE CVE VULNERABILITY TITLE RISK
2019-04-22 CVE-2011-3147 Information Exposure vulnerability in Openstack Nova
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
network
low complexity
openstack CWE-200
8.6
2018-02-19 CVE-2017-18191 An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1.
network
low complexity
openstack redhat
7.5
2017-12-05 CVE-2017-17051 Resource Exhaustion vulnerability in Openstack Nova 16.0.3
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.
network
low complexity
openstack CWE-400
8.6
2017-11-14 CVE-2017-16239 Unspecified vulnerability in Openstack Nova
In OpenStack Nova through 14.0.9, 15.x through 15.0.7, and 16.x through 16.0.2, by rebuilding an instance, an authenticated user may be able to circumvent the Filter Scheduler bypassing imposed filters (for example, the ImagePropertiesFilter or the IsolatedHostsFilter).
network
low complexity
openstack
6.5
2017-03-21 CVE-2017-7214 Information Exposure Through Log Files vulnerability in Openstack Nova
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
network
low complexity
openstack CWE-532
critical
9.8
2016-10-07 CVE-2015-5162 Resource Management Errors vulnerability in Openstack Cinder, Glance and Nova
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
network
low complexity
openstack CWE-399
7.5
2016-04-12 CVE-2016-2140 Information Exposure vulnerability in Openstack Nova
The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images is set to false, allows remote authenticated users to read arbitrary files via a crafted qcow2 header in an ephemeral or root disk.
network
high complexity
openstack CWE-200
5.3
2016-01-15 CVE-2015-8749 Information Exposure vulnerability in Openstack Nova
The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.
network
high complexity
openstack CWE-200
5.9
2016-01-12 CVE-2015-7548 Information Exposure vulnerability in Openstack Nova
OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot.
network
high complexity
openstack CWE-200
3.5