Openstack

Nova

38 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.71%
  • Veröffentlicht 24.07.2024 05:15:12
  • Zuletzt bearbeitet 19.03.2025 15:15:48

In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convinc...

  • EPSS 0.07%
  • Veröffentlicht 05.07.2024 02:15:09
  • Zuletzt bearbeitet 21.11.2024 09:15:02

An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 image that references a specific data file path, an...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 26.01.2023 22:15:25
  • Zuletzt bearbeitet 31.03.2025 17:15:39

An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image ...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 03.08.2022 07:15:07
  • Zuletzt bearbeitet 21.11.2024 07:14:54

An issue was discovered in OpenStack Nova before 23.2.2, 24.x before 24.1.2, and 25.x before 25.0.2. By creating a neutron port with the direct vnic_type, creating an instance bound to that port, and then changing the vnic_type of the bound port to m...

Exploit
  • EPSS 89.55%
  • Veröffentlicht 02.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:22:04

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 26.08.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:07:58

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to dest...

  • EPSS 0.13%
  • Veröffentlicht 19.02.2020 03:15:10
  • Zuletzt bearbeitet 21.11.2024 02:40:53

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova...

  • EPSS 0.11%
  • Veröffentlicht 05.12.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 01:47:18

OpenStack nova base images permissions are world readable

Exploit
  • EPSS 0.41%
  • Veröffentlicht 26.11.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 01:31:47

OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https cou...

  • EPSS 1.4%
  • Veröffentlicht 09.08.2019 19:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:44

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be le...