Openstack

Essex

15 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.43%
  • Veröffentlicht 22.03.2013 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via...

  • EPSS 1.04%
  • Veröffentlicht 22.03.2013 21:55:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.

  • EPSS 0.05%
  • Veröffentlicht 08.03.2013 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

  • EPSS 0.04%
  • Veröffentlicht 08.03.2013 21:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading...

  • EPSS 1.15%
  • Veröffentlicht 13.02.2013 16:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.

  • EPSS 0.31%
  • Veröffentlicht 18.12.2012 01:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token f...

  • EPSS 1.4%
  • Veröffentlicht 11.11.2012 13:00:59
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CV...

  • EPSS 0.99%
  • Veröffentlicht 11.11.2012 13:00:58
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.

  • EPSS 1.76%
  • Veröffentlicht 05.09.2012 23:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 31.07.2012 10:45:42
  • Zuletzt bearbeitet 11.04.2025 00:51:21

OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating n...