VendorsOpenStackessexany version
Vulnerabilities

OpenStack Compute (Essex) any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2013-0261
Packstack: packstack: arbitrary file overwrite via symlink attack
Published 2013-03-08 · Modified
8.8EPSS 0.003
CVE-2013-0208
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
Published 2013-02-13 · Modified
6.5EPSS 0.025
CVE-2013-0266
Puppetlabs-cinder: packstack: openstack: puppetlabs-cinder: information disclosure of openstack administrative passwords due to world-readable configuration files.
Published 2013-03-08 · Modified
5.5EPSS 0.003
CVE-2012-3426
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating new tokens through token chaining, (2) leveraging possession of a token for a disabled user account, or (3) leveraging possession of a token for an account with a changed password.
Published 2012-07-31 · Modified
4.9EPSS 0.023
CVE-2012-0030
Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modified project_id URI parameter.
Published 2012-01-13 · Modified
4.9EPSS 0.017