Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2013-1793
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
openstack-utils openstack-db has insecure password creation
0
Attacker Value
Unknown
CVE-2012-6120
Disclosure Date: April 10, 2013 (last updated October 05, 2023)
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
0
Attacker Value
Unknown
CVE-2013-1815
Disclosure Date: April 10, 2013 (last updated October 05, 2023)
PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file.
0
Attacker Value
Unknown
CVE-2013-1664
Disclosure Date: April 03, 2013 (last updated October 05, 2023)
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex, Folsom, and Grizzly; Compute (Nova) Essex and Folsom; Cinder Folsom; Django; and possibly other products allow remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack.
0
Attacker Value
Unknown
CVE-2013-1665
Disclosure Date: April 03, 2013 (last updated October 05, 2023)
The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) attack.
0
Attacker Value
Unknown
CVE-2013-0335
Disclosure Date: March 22, 2013 (last updated October 05, 2023)
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
0
Attacker Value
Unknown
CVE-2013-1838
Disclosure Date: March 22, 2013 (last updated October 05, 2023)
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
0
Attacker Value
Unknown
CVE-2013-0266
Disclosure Date: March 08, 2013 (last updated October 05, 2023)
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.
0
Attacker Value
Unknown
CVE-2013-0261
Disclosure Date: March 08, 2013 (last updated October 05, 2023)
(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
0
Attacker Value
Unknown
CVE-2013-0208
Disclosure Date: February 13, 2013 (last updated October 05, 2023)
The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from other users' volumes via a volume id in the block_device_mapping parameter.
0