Skip to main content

Vendor/product archive

openstack / essex CVEs

Beta · best-effort

16 CVEs tagged to openstack / essex0 Critical, 1 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2013-0266

Published Mar 8, 2013

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0261

Published Mar 8, 2013

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5571

Published Dec 18, 2012

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3542

Published Sep 5, 2012

OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a reque…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3360

Published Jul 22, 2012

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0030

Published Jan 13, 2012

Nova 2011.3 and Essex, when using the OpenStack API, allows remote authenticated users to bypass access restrictions for tenants of other users via an OSAPI request with a modifie…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1