- EPSS 1.43%
- Veröffentlicht 22.03.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via...
- EPSS 1.04%
- Veröffentlicht 22.03.2013 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
CVE-2013-0261
- EPSS 0.05%
- Veröffentlicht 08.03.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
CVE-2013-0266
- EPSS 0.04%
- Veröffentlicht 08.03.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading...
CVE-2013-0208
- EPSS 1.15%
- Veröffentlicht 13.02.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
CVE-2012-5571
- EPSS 0.31%
- Veröffentlicht 18.12.2012 01:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Keystone Essex (2012.1) and Folsom (2012.2) does not properly handle EC2 tokens when the user role has been removed from a tenant, which allows remote authenticated users to bypass intended authorization restrictions by leveraging a token f...
CVE-2012-5482
- EPSS 1.4%
- Veröffentlicht 11.11.2012 13:00:59
- Zuletzt bearbeitet 11.04.2025 00:51:21
The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request. NOTE: this vulnerability exists because of an incomplete fix for CV...
CVE-2012-4573
- EPSS 0.99%
- Veröffentlicht 11.11.2012 13:00:58
- Zuletzt bearbeitet 11.04.2025 00:51:21
The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected images via an image deletion request, a different vulnerability than CVE-2012-5482.
CVE-2012-3542
- EPSS 1.76%
- Veröffentlicht 05.09.2012 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE...
CVE-2012-3426
- EPSS 0.21%
- Veröffentlicht 31.07.2012 10:45:42
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Keystone before 2012.1.1, as used in OpenStack Folsom before Folsom-1 and OpenStack Essex, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization restrictions by (1) creating n...