openstack kayıtları
openstack üreticisine ait 292 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %94,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor42
- CWE-264 Permissions, Privileges, and Access Controls37
- CWE-399 Resource Management Errors22
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-20 Improper Input Validation13
- CWE-863 Incorrect Authorization12
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
292 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
55Planlayın | CVE-2017-18017İstismar yok | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attaclinux · linux kernel · CWE-416 | Kritik9,8 | — | %52,8 | 3 Oca 2018 |
42Planlayın | CVE-2017-16613İstismar yok | An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.openstack · swauth · CWE-287 | Kritik9,8 | — | %8,4 | 21 Kas 2017 |
41Planlayın | CVE-2012-4406İstismar yok | OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadataopenstack · swift · CWE-502 | Kritik9,8 | — | %6,6 | 22 Eki 2012 |
40Planlayın | CVE-2020-26943İstismar yok | An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.openstack · blazar-dashboard | Kritik9,9 | — | %3,3 | 16 Eki 2020 |
40Planlayın | CVE-2016-4972İstismar yok | OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)openstack · mitaka-murano · CWE-20 | Kritik9,8 | — | %3,2 | 26 Eyl 2016 |
40Planlayın | CVE-2017-7214İstismar yok | An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.openstack · nova · CWE-532 | Kritik9,8 | — | %2,3 | 21 Mar 2017 |
40Planlayın | CVE-2013-2166İstismar yok | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypassopenstack · python-keystoneclient · CWE-326 | Kritik9,8 | — | %2,1 | 10 Ara 2019 |
40Planlayın | CVE-2013-2167İstismar yok | python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypassopenstack · python-keystoneclient · CWE-345 | Kritik9,8 | — | %2,0 | 10 Ara 2019 |
40Planlayın | CVE-2016-7404İstismar yok | OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.openstack · magnum · CWE-200 | Kritik9,8 | — | %1,9 | 21 Haz 2019 |
39İzleyin | CVE-2024-28718İstismar yok | An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.openstack · magnum · CWE-367 | Kritik9,8 | — | %1,1 | 12 Nis 2024 |
39İzleyin | CVE-2026-31072İstismar yok | The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCCWE-502 | Kritik9,8 | — | %1,0 | 19 May 2026 |
39İzleyin | CVE-2026-41283İstismar yok | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.openstack · mistral · CWE-863 | Kritik9,9 | — | %0,9 | 4 Haz 2026 |
39İzleyin | CVE-2026-22797İstismar yok | An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1openstack · keystonemiddleware · CWE-290 | Kritik9,9 | — | %0,7 | 19 Oca 2026 |
37İzleyin | CVE-2015-8914İstismar yok | The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofinopenstack · neutron · CWE-254 | Kritik9,1 | — | %4,3 | 17 Haz 2016 |
37İzleyin | CVE-2014-0187İstismar yok | The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to byopenstack · neutron · CWE-264 | Kritik9,0 | — | %2,9 | 28 Nis 2014 |
37İzleyin | CVE-2019-15753İstismar yok | In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligatopenstack · os-vif · CWE-770 | Kritik9,1 | — | %2,6 | 28 Ağu 2019 |
37İzleyin | CVE-2019-10141İstismar yok | A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.openstack · ironic-inspector · CWE-89 | Kritik9,1 | — | %2,5 | 30 Tem 2019 |
36İzleyin | CVE-2020-12691İstismar yok | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-863 | Yüksek8,8 | — | %4,9 | 6 May 2020 |
36İzleyin | CVE-2020-12690İstismar yok | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-613 | Yüksek8,8 | — | %1,9 | 6 May 2020 |
36İzleyin | CVE-2019-19687İstismar yok | OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.openstack · keystone · CWE-522 | Yüksek8,8 | — | %1,8 | 9 Ara 2019 |
36İzleyin | CVE-2021-38598İstismar yok | OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtabopenstack · neutron · CWE-290 | Kritik9,1 | — | %1,2 | 23 Ağu 2021 |
36İzleyin | CVE-2026-28370İstismar yok | In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger codopenstack · vitrage · CWE-95 | Kritik9,1 | — | %0,8 | 27 Şub 2026 |
35İzleyin | CVE-2017-17051İstismar yok | An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.openstack · nova · CWE-400 | Yüksek8,6 | — | %2,0 | 5 Ara 2017 |
35İzleyin | CVE-2020-12689İstismar yok | An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.openstack · keystone · CWE-269 | Yüksek8,8 | — | %1,6 | 6 May 2020 |
35İzleyin | CVE-2018-10898İstismar yok | A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.openstack · tripleo heat templates · CWE-798 | Yüksek8,8 | — | %0,9 | 30 Tem 2018 |
- CVE-2017-1801755Planlayın
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attac
KritikCVSS 9,8İstismar yokEPSS %53linux · linux kernel3 Oca 2018
- CVE-2017-1661342Planlayın
An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1.
KritikCVSS 9,8İstismar yokEPSS %8openstack · swauth21 Kas 2017
- CVE-2012-440641Planlayın
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata
KritikCVSS 9,8İstismar yokEPSS %7openstack · swift22 Eki 2012
- CVE-2020-2694340Planlayın
An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0.
KritikCVSS 9,9İstismar yokEPSS %3openstack · blazar-dashboard16 Eki 2020
- CVE-2016-497240Planlayın
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka)
KritikCVSS 9,8İstismar yokEPSS %3openstack · mitaka-murano26 Eyl 2016
- CVE-2017-721440Planlayın
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
KritikCVSS 9,8İstismar yokEPSS %2openstack · nova21 Mar 2017
- CVE-2013-216640Planlayın
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
KritikCVSS 9,8İstismar yokEPSS %2openstack · python-keystoneclient10 Ara 2019
- CVE-2013-216740Planlayın
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache signing bypass
KritikCVSS 9,8İstismar yokEPSS %2openstack · python-keystoneclient10 Ara 2019
- CVE-2016-740440Planlayın
OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances.
KritikCVSS 9,8İstismar yokEPSS %2openstack · magnum21 Haz 2019
- CVE-2024-2871839İzleyin
An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py.
KritikCVSS 9,8İstismar yokEPSS %1openstack · magnum12 Nis 2024
- CVE-2026-3107239İzleyin
The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RC
KritikCVSS 9,8İstismar yokEPSS %119 May 2026
- CVE-2026-4128339İzleyin
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed.
KritikCVSS 9,9İstismar yokEPSS %1openstack · mistral4 Haz 2026
- CVE-2026-2279739İzleyin
An issue was discovered in OpenStack keystonemiddleware 10.5 through 10.7 before 10.7.2, 10.8 and 10.9 before 10.9.1, and 10.10 through 10.1
KritikCVSS 9,9İstismar yokEPSS %1openstack · keystonemiddleware19 Oca 2026
- CVE-2015-891437İzleyin
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofin
KritikCVSS 9,1İstismar yokEPSS %4openstack · neutron17 Haz 2016
- CVE-2014-018737İzleyin
The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to by
KritikCVSS 9,0İstismar yokEPSS %3openstack · neutron28 Nis 2014
- CVE-2019-1575337İzleyin
In OpenStack os-vif 1.15.x before 1.15.2, and 1.16.0, a hard-coded MAC aging time of 0 disables MAC learning in linuxbridge, forcing obligat
KritikCVSS 9,1İstismar yokEPSS %3openstack · os-vif28 Ağu 2019
- CVE-2019-1014137İzleyin
A vulnerability was found in openstack-ironic-inspector all versions excluding 5.0.2, 6.0.3, 7.2.4, 8.0.3 and 8.2.1.
KritikCVSS 9,1İstismar yokEPSS %2openstack · ironic-inspector30 Tem 2019
- CVE-2020-1269136İzleyin
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
YüksekCVSS 8,8İstismar yokEPSS %5openstack · keystone6 May 2020
- CVE-2020-1269036İzleyin
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
YüksekCVSS 8,8İstismar yokEPSS %2openstack · keystone6 May 2020
- CVE-2019-1968736İzleyin
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API.
YüksekCVSS 8,8İstismar yokEPSS %2openstack · keystone9 Ara 2019
- CVE-2021-3859836İzleyin
OpenStack Neutron before 16.4.1, 17.x before 17.1.3, and 18.0.0 allows hardware address impersonation when the linuxbridge driver with ebtab
KritikCVSS 9,1İstismar yokEPSS %1openstack · neutron23 Ağu 2021
- CVE-2026-2837036İzleyin
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage API may trigger cod
KritikCVSS 9,1İstismar yokEPSS %1openstack · vitrage27 Şub 2026
- CVE-2017-1705135İzleyin
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3.
YüksekCVSS 8,6İstismar yokEPSS %2openstack · nova5 Ara 2017
- CVE-2020-1268935İzleyin
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0.
YüksekCVSS 8,8İstismar yokEPSS %2openstack · keystone6 May 2020
- CVE-2018-1089835İzleyin
A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40.
YüksekCVSS 8,8İstismar yokEPSS %1openstack · tripleo heat templates30 Tem 2018