Vulnerabilities > Openstack > High

DATE CVE VULNERABILITY TITLE RISK
2019-12-09 CVE-2019-19687 Insufficiently Protected Credentials vulnerability in Openstack Keystone 15.0.0/16.0.0
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.
network
low complexity
openstack CWE-522
8.8
2019-11-12 CVE-2012-1572 Resource Exhaustion vulnerability in multiple products
OpenStack Keystone: extremely long passwords can crash Keystone by exhausting stack space
network
low complexity
openstack debian CWE-400
7.5
2019-06-03 CVE-2019-3895 An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director.
network
low complexity
openstack redhat
8.0
2019-04-22 CVE-2011-3147 Information Exposure vulnerability in Openstack Nova
Versions of nova before 2012.1 could expose hypervisor host files to a guest operating system when processing a maliciously constructed qcow filesystem.
network
low complexity
openstack CWE-200
8.6
2019-03-26 CVE-2019-3830 Information Exposure Through Log Files vulnerability in multiple products
A vulnerability was found in ceilometer before version 12.0.0.0rc1.
local
low complexity
openstack redhat CWE-532
7.8
2019-03-26 CVE-2018-16856 Information Exposure Through Log Files vulnerability in multiple products
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users.
network
low complexity
openstack redhat CWE-532
7.5
2018-08-27 CVE-2017-15139 Information Exposure vulnerability in multiple products
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data.
network
low complexity
openstack redhat CWE-200
7.5
2018-08-22 CVE-2017-2627 Path Traversal vulnerability in multiple products
A flaw was found in openstack-tripleo-common as shipped with Red Hat Openstack Enterprise 10 and 11.
local
low complexity
redhat openstack CWE-22
8.2
2018-07-30 CVE-2018-10898 Use of Hard-coded Credentials vulnerability in multiple products
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.
low complexity
redhat openstack CWE-798
8.8
2018-04-24 CVE-2016-9599 Improper Access Control vulnerability in multiple products
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values.
network
high complexity
openstack redhat CWE-284
7.5