Vulnerabilities > Openstack

DATE CVE VULNERABILITY TITLE RISK
2014-10-31 CVE-2014-8578 Cross-Site Scripting vulnerability in Openstack Horizon
Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475.
network
openstack CWE-79
3.5
2014-10-31 CVE-2014-8333 Resource Management Errors vulnerability in multiple products
The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.
network
low complexity
redhat openstack CWE-399
4.0
2014-10-17 CVE-2014-7960 Resource Management Errors vulnerability in Openstack Swift
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.
network
low complexity
openstack CWE-399
4.0
2014-10-15 CVE-2014-8750 Race Condition vulnerability in Openstack Nova
Race condition in the VMware driver in OpenStack Compute (Nova) before 2014.1.4 and 2014.2 before 2014.2rc1 allows remote authenticated users to access unintended consoles by spawning an instance that triggers the same VNC port to be allocated to two different instances.
network
low complexity
openstack CWE-362
6.5
2014-10-08 CVE-2014-7231 Information Exposure vulnerability in multiple products
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
local
low complexity
openstack redhat CWE-200
2.1
2014-10-08 CVE-2014-7230 Information Exposure vulnerability in multiple products
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
local
low complexity
openstack redhat canonical CWE-200
2.1
2014-10-02 CVE-2014-7144 Cryptographic Issues vulnerability in Openstack Keystonemiddleware and Python-Keystoneclient
OpenStack keystonemiddleware (formerly python-keystoneclient) 0.x before 0.11.0 and 1.x before 1.2.0 disables certification verification when the "insecure" option is set in a paste configuration (paste.ini) file regardless of the value, which allows remote attackers to conduct man-in-the-middle attacks via a crafted certificate.
network
openstack CWE-310
4.3
2014-10-02 CVE-2014-6414 Permissions, Privileges, and Access Controls vulnerability in multiple products
OpenStack Neutron before 2014.2.4 and 2014.1 before 2014.1.2 allows remote authenticated users to set admin network attributes to default values via unspecified vectors.
network
low complexity
openstack canonical CWE-264
4.0
2014-08-25 CVE-2014-5356 Permissions, Privileges, and Access Controls vulnerability in multiple products
OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.
network
low complexity
openstack canonical CWE-264
4.0
2014-08-25 CVE-2014-5253 Credentials Management vulnerability in multiple products
OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated users to retain access via a domain-scoped token for that domain.
4.9