Записи openstack
292 опубликованных записей вендора openstack.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 94,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42
- CWE-264 Permissions, Privileges, and Access Controls37
- CWE-399 Resource Management Errors22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-20 Improper Input Validation13
- CWE-863 Incorrect Authorization12
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
292 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
55В плане | CVE-2017-18017Эксплойта нет | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Критическая9,8 | — | 52,8 % | 3 янв. 2018 г. |
42В плане | CVE-2017-16613Эксплойта нет | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.openstack · swauth · CWE-287 | Критическая9,8 | — | 8,4 % | 21 нояб. 2017 г. |
41В плане | CVE-2012-4406Эксплойта нет | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadataopenstack · swift · CWE-502 | Критическая9,8 | — | 6,6 % | 22 окт. 2012 г. |
40В плане | CVE-2020-26943Эксплойта нет | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.openstack · blazar-dashboard | Критическая9,9 | — | 3,3 % | 16 окт. 2020 г. |
40В плане | CVE-2016-4972Эксплойта нет | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)openstack · mitaka-murano · CWE-20 | Критическая9,8 | — | 3,2 % | 26 сент. 2016 г. |
40В плане | CVE-2017-7214Эксплойта нет | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Критическая9,8 | — | 2,3 % | 21 мар. 2017 г. |
40В плане | CVE-2013-2166Эксплойта нет | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypassopenstack · python-keystoneclient · CWE-326 | Критическая9,8 | — | 2,1 % | 10 дек. 2019 г. |
40В плане | CVE-2013-2167Эксплойта нет | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypassopenstack · python-keystoneclient · CWE-345 | Критическая9,8 | — | 2,0 % | 10 дек. 2019 г. |
40В плане | CVE-2016-7404Эксплойта нет | OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.openstack · magnum · CWE-200 | Критическая9,8 | — | 1,9 % | 21 июн. 2019 г. |
39Наблюдать | CVE-2024-28718Эксплойта нет | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.openstack · magnum · CWE-367 | Критическая9,8 | — | 1,1 % | 12 апр. 2024 г. |
39Наблюдать | CVE-2026-31072Эксплойта нет | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCCWE-502 | Критическая9,8 | — | 1,0 % | 19 мая 2026 г. |
39Наблюдать | CVE-2026-41283Эксплойта нет | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.openstack · mistral · CWE-863 | Критическая9,9 | — | 0,9 % | 4 июн. 2026 г. |
39Наблюдать | CVE-2026-22797Эксплойта нет | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1openstack · keystonemiddleware · CWE-290 | Критическая9,9 | — | 0,7 % | 19 янв. 2026 г. |
37Наблюдать | CVE-2015-8914Эксплойта нет | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofinopenstack · neutron · CWE-254 | Критическая9,1 | — | 4,3 % | 17 июн. 2016 г. |
37Наблюдать | CVE-2014-0187Эксплойта нет | The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to byopenstack · neutron · CWE-264 | Критическая9,0 | — | 2,9 % | 28 апр. 2014 г. |
37Наблюдать | CVE-2019-15753Эксплойта нет | In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatopenstack · os-vif · CWE-770 | Критическая9,1 | — | 2,6 % | 28 авг. 2019 г. |
37Наблюдать | CVE-2019-10141Эксплойта нет | A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.openstack · ironic-inspector · CWE-89 | Критическая9,1 | — | 2,5 % | 30 июл. 2019 г. |
36Наблюдать | CVE-2020-12691Эксплойта нет | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-863 | Высокая8,8 | — | 4,9 % | 6 мая 2020 г. |
36Наблюдать | CVE-2020-12690Эксплойта нет | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-613 | Высокая8,8 | — | 1,9 % | 6 мая 2020 г. |
36Наблюдать | CVE-2019-19687Эксплойта нет | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.openstack · keystone · CWE-522 | Высокая8,8 | — | 1,8 % | 9 дек. 2019 г. |
36Наблюдать | CVE-2021-38598Эксплойта нет | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtabopenstack · neutron · CWE-290 | Критическая9,1 | — | 1,2 % | 23 авг. 2021 г. |
36Наблюдать | CVE-2026-28370Эксплойта нет | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger codopenstack · vitrage · CWE-95 | Критическая9,1 | — | 0,8 % | 27 февр. 2026 г. |
35Наблюдать | CVE-2017-17051Эксплойта нет | An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.openstack · nova · CWE-400 | Высокая8,6 | — | 2,0 % | 5 дек. 2017 г. |
35Наблюдать | CVE-2020-12689Эксплойта нет | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-269 | Высокая8,8 | — | 1,6 % | 6 мая 2020 г. |
35Наблюдать | CVE-2018-10898Эксплойта нет | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.openstack · tripleo heat templates · CWE-798 | Высокая8,8 | — | 0,9 % | 30 июл. 2018 г. |
- CVE-2017-1801755В плане
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
КритическаяCVSS 9,8Эксплойта нетEPSS 53 %linux · linux kernel3 янв. 2018 г.
- CVE-2017-1661342В плане
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %openstack · swauth21 нояб. 2017 г.
- CVE-2012-440641В плане
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %openstack · swift22 окт. 2012 г.
- CVE-2020-2694340В плане
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.
КритическаяCVSS 9,9Эксплойта нетEPSS 3 %openstack · blazar-dashboard16 окт. 2020 г.
- CVE-2016-497240В плане
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %openstack · mitaka-murano26 сент. 2016 г.
- CVE-2017-721440В плане
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openstack · nova21 мар. 2017 г.
- CVE-2013-216640В плане
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openstack · python-keystoneclient10 дек. 2019 г.
- CVE-2013-216740В плане
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openstack · python-keystoneclient10 дек. 2019 г.
- CVE-2016-740440В плане
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openstack · magnum21 июн. 2019 г.
- CVE-2024-2871839Наблюдать
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openstack · magnum12 апр. 2024 г.
- CVE-2026-3107239Наблюдать
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %19 мая 2026 г.
- CVE-2026-4128339Наблюдать
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %openstack · mistral4 июн. 2026 г.
- CVE-2026-2279739Наблюдать
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %openstack · keystonemiddleware19 янв. 2026 г.
- CVE-2015-891437Наблюдать
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofin
КритическаяCVSS 9,1Эксплойта нетEPSS 4 %openstack · neutron17 июн. 2016 г.
- CVE-2014-018737Наблюдать
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to by
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %openstack · neutron28 апр. 2014 г.
- CVE-2019-1575337Наблюдать
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligat
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %openstack · os-vif28 авг. 2019 г.
- CVE-2019-1014137Наблюдать
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %openstack · ironic-inspector30 июл. 2019 г.
- CVE-2020-1269136Наблюдать
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %openstack · keystone6 мая 2020 г.
- CVE-2020-1269036Наблюдать
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openstack · keystone6 мая 2020 г.
- CVE-2019-1968736Наблюдать
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openstack · keystone9 дек. 2019 г.
- CVE-2021-3859836Наблюдать
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %openstack · neutron23 авг. 2021 г.
- CVE-2026-2837036Наблюдать
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger cod
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %openstack · vitrage27 февр. 2026 г.
- CVE-2017-1705135Наблюдать
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.
ВысокаяCVSS 8,6Эксплойта нетEPSS 2 %openstack · nova5 дек. 2017 г.
- CVE-2020-1268935Наблюдать
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openstack · keystone6 мая 2020 г.
- CVE-2018-1089835Наблюдать
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openstack · tripleo heat templates30 июл. 2018 г.