Search CVE reports


Toggle filters

1 – 6 of 6 results


CVE-2023-6110

Medium priority

Some fixes available 2 of 4

A flaw was found in OpenStack. When a user tries to delete a non-existing access rule in it's scope, it deletes other existing access rules which are not associated with any application credentials.

1 affected package

python-openstackclient

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-openstackclient Not affected Fixed Fixed Needs evaluation
Show less packages

CVE-2022-3261

Medium priority
Needs evaluation

A flaw was found in OpenStack. Multiple components show plain-text passwords in /var/log/messages during the OpenStack overcloud update run, leading to a disclosure of sensitive information problem.

1 affected package

openstack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openstack Not in release Not in release Not in release Ignored
Show less packages

CVE-2022-38065

Medium priority
Ignored

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased...

2 affected packages

openstack, python-oslo.privsep

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openstack Not in release Not in release Not in release
python-oslo.privsep Ignored Ignored Ignored
Show less packages

CVE-2020-29565

Medium priority
Fixed

An issue was discovered in OpenStack Horizon before 15.3.2, 16.x before 16.2.1, 17.x and 18.x before 18.3.3, 18.4.x, and 18.5.x. There is a lack of validation of the "next" parameter, which would allow someone to supply...

2 affected packages

horizon, openstack

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
horizon Fixed Fixed
openstack Not in release Not in release
Show less packages

CVE-2015-3156

Medium priority
Vulnerable

The _write_config function in trove/guestagent/datastore/experimental/mongodb/service.py, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/config.py, write_config function...

1 affected package

openstack-trove

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openstack-trove Not in release Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2014-8124

Medium priority
Fixed

OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a...

2 affected packages

horizon, python-django-openstack-auth

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
horizon
python-django-openstack-auth
Show less packages