Skip to content
Noroxi

openstack records

292 published records for vendor openstack.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
7
With a fix record
94.2%
Median publish → KEV
No record has entered KEV

All records

292 records
  • The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac

    CriticalCVSS 9.8No exploitEPSS 53%

    linux · linux kernelJan 3, 2018

  • An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.

    CriticalCVSS 9.8No exploitEPSS 8%

    openstack · swauthNov 21, 2017

  • OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata

    CriticalCVSS 9.8No exploitEPSS 7%

    openstack · swiftOct 22, 2012

  • An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.

    CriticalCVSS 9.9No exploitEPSS 3%

    openstack · blazar-dashboardOct 16, 2020

  • OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)

    CriticalCVSS 9.8No exploitEPSS 3%

    openstack · mitaka-muranoSep 26, 2016

  • An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.

    CriticalCVSS 9.8No exploitEPSS 2%

    openstack · novaMar 21, 2017

  • python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

    CriticalCVSS 9.8No exploitEPSS 2%

    openstack · python-keystoneclientDec 10, 2019

  • python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass

    CriticalCVSS 9.8No exploitEPSS 2%

    openstack · python-keystoneclientDec 10, 2019

  • OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.

    CriticalCVSS 9.8No exploitEPSS 2%

    openstack · magnumJun 21, 2019

  • An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.

    CriticalCVSS 9.8No exploitEPSS 1%

    openstack · magnumApr 12, 2024

  • The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC

    CriticalCVSS 9.8No exploitEPSS 1%

    May 19, 2026

  • OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.

    CriticalCVSS 9.9No exploitEPSS 1%

    openstack · mistralJun 4, 2026

  • An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1

    CriticalCVSS 9.9No exploitEPSS 1%

    openstack · keystonemiddlewareJan 19, 2026

  • CVE-2015-8914
    37Monitor

    The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofin

    CriticalCVSS 9.1No exploitEPSS 4%

    openstack · neutronJun 17, 2016

  • CVE-2014-0187
    37Monitor

    The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to by

    CriticalCVSS 9.0No exploitEPSS 3%

    openstack · neutronApr 28, 2014

  • In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligat

    CriticalCVSS 9.1No exploitEPSS 3%

    openstack · os-vifAug 28, 2019

  • A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.

    CriticalCVSS 9.1No exploitEPSS 2%

    openstack · ironic-inspectorJul 30, 2019

  • An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.

    HighCVSS 8.8No exploitEPSS 5%

    openstack · keystoneMay 6, 2020

  • An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.

    HighCVSS 8.8No exploitEPSS 2%

    openstack · keystoneMay 6, 2020

  • OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.

    HighCVSS 8.8No exploitEPSS 2%

    openstack · keystoneDec 9, 2019

  • OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab

    CriticalCVSS 9.1No exploitEPSS 1%

    openstack · neutronAug 23, 2021

  • In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger cod

    CriticalCVSS 9.1No exploitEPSS 1%

    openstack · vitrageFeb 27, 2026

  • An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.

    HighCVSS 8.6No exploitEPSS 2%

    openstack · novaDec 5, 2017

  • An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.

    HighCVSS 8.8No exploitEPSS 2%

    openstack · keystoneMay 6, 2020

  • A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.

    HighCVSS 8.8No exploitEPSS 1%

    openstack · tripleo heat templatesJul 30, 2018