Vulnerabilities > Openstack > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-19 CVE-2017-18191 An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1.
network
low complexity
openstack redhat
7.5
2017-12-05 CVE-2017-17051 Resource Exhaustion vulnerability in Openstack Nova 16.0.3
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.
network
low complexity
openstack CWE-400
8.6
2017-08-18 CVE-2017-12440 Missing Authentication for Critical Function vulnerability in Openstack 07132017
Aodh as packaged in Openstack Ocata and Newton before change-ID I8fd11a7f9fe3c0ea5f9843a89686ac06713b7851 and before Pike-rc1 does not verify that trust IDs belong to the user when creating alarm action with the scheme trust+http, which allows remote authenticated users with knowledge of trust IDs where Aodh is the trustee to obtain a Keystone token and perform unspecified authenticated actions by adding an alarm action with the scheme trust+http, and providing a trust id where Aodh is the trustee.
network
high complexity
openstack CWE-306
7.5
2017-06-19 CVE-2017-1000366 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution.
7.8
2017-04-12 CVE-2017-5936 OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.
network
low complexity
canonical openstack
7.5
2016-10-07 CVE-2015-5162 Resource Management Errors vulnerability in Openstack Cinder, Glance and Nova
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
network
low complexity
openstack CWE-399
7.5
2016-06-17 CVE-2016-5363 7PK - Security Features vulnerability in Openstack Neutron
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.
network
low complexity
openstack CWE-254
8.2
2016-06-17 CVE-2016-5362 7PK - Security Features vulnerability in Openstack Neutron
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.
network
low complexity
openstack CWE-254
8.2
2016-04-15 CVE-2015-5271 Information Exposure vulnerability in multiple products
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
network
low complexity
redhat openstack CWE-200
7.5
2016-04-11 CVE-2015-5303 7PK - Security Features vulnerability in Openstack Tripleo Heat Templates
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
network
low complexity
openstack CWE-254
7.5