Search CVE reports


Toggle filters

31 – 40 of 68 results


CVE-2014-3517

Medium priority
Fixed

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2014-2573

Negligible priority
Ignored

The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2014-0167

Low priority
Fixed

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2014-0134

Medium priority
Fixed

The instance rescue mode in OpenStack Compute (Nova) 2013.2 before 2013.2.3 and Icehouse before 2014.1, when using libvirt to spawn images and use_cow_images is set to false, allows remote authenticated users to read certain...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-7130

Medium priority

Some fixes available 2 of 4

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files,...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-7048

Low priority
Ignored

OpenStack Compute (Nova) Grizzly 2013.1.4, Havana 2013.2.1, and earlier uses world-writable and world-readable permissions for the temporary directory used to store live snapshots, which allows local users to read and modify live...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-6491

Medium priority

Some fixes available 3 of 4

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

5 affected packages

cinder, keystone, neutron, nova, quantum

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cinder
keystone
neutron
nova
quantum
Show less packages

CVE-2013-6437

Medium priority
Ignored

The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages

CVE-2013-6419

Medium priority
Ignored

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the...

2 affected packages

neutron, nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
neutron
nova
Show less packages

CVE-2013-4497

Medium priority
Ignored

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to...

1 affected package

nova

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nova
Show less packages