Show filters
257 Total Results
Displaying 11-20 of 257
Sort by:
Attacker Value
Unknown

CVE-2022-4134

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
A flaw was found in openstack-glance. This issue could allow a remote, authenticated attacker to tamper with images, compromising the integrity of virtual machines created using these modified images.
Attacker Value
Unknown

CVE-2022-3277

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests, this could lead to a denial of service.
Attacker Value
Unknown

CVE-2022-47951

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
Attacker Value
Unknown

CVE-2022-47950

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).
Attacker Value
Unknown

CVE-2022-3100

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
A flaw was found in the openstack-barbican component. This issue allows an access policy bypass via a query string when accessing the API.
Attacker Value
Unknown

CVE-2022-38060

Disclosure Date: December 20, 2022 (last updated October 08, 2023)
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
Attacker Value
Unknown

CVE-2022-23451

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
An authorization flaw was found in openstack-barbican. The default policy rules for the secret metadata API allowed any authenticated user to add, modify, or delete metadata from any secret regardless of ownership. This flaw allows an attacker on the network to modify or delete protected data, causing a denial of service by consuming protected resources.
Attacker Value
Unknown

CVE-2022-2447

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected.
Attacker Value
Unknown

CVE-2022-23452

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
An authorization flaw was found in openstack-barbican, where anyone with an admin role could add secrets to a different project container. This flaw allows an attacker on the network to consume protected resources and cause a denial of service.
Attacker Value
Unknown

CVE-2022-0718

Disclosure Date: August 29, 2022 (last updated October 08, 2023)
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.