Skip to main content

Vendor/product archive

openstack / folsom CVEs

Beta · best-effort

26 CVEs tagged to openstack / folsom0 Critical, 2 High, 17 Medium, 7 Low, 0 Unrated.

CVE-2013-1665

Published Apr 3, 2013

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1865

Published Mar 22, 2013

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0266

Published Mar 8, 2013

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0261

Published Mar 8, 2013

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5625

Published Dec 26, 2012

OpenStack Compute (Nova) Folsom before 2012.2.2 and Grizzly, when using libvirt and LVM backed instances, does not properly clear physical volume (PV) content when reallocating fo…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5571

Published Dec 18, 2012

A flaw was found in OpenStack Keystone. This vulnerability allows remote authenticated users to bypass intended authorization restrictions. This occurs because OpenStack Keystone…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5563

Published Dec 18, 2012

OpenStack Keystone, as used in OpenStack Folsom 2012.2, does not properly implement token expiration, which allows remote authenticated users to bypass intended authorization rest…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3447

Published Aug 20, 2012

virt/disk/api.py in OpenStack Compute (Nova) 2012.1.x before 2012.1.2 and Folsom before Folsom-3 allows remote authenticated users to overwrite arbitrary files via a symlink attac…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3360

Published Jul 22, 2012

Directory traversal vulnerability in virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2) and Essex (2012.1), when used over libvirt-based hypervisors, allows remote authe…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2