cinder vulnerabilities
CVEs whose affected-version data names the cinder package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
8 CVEsRSS
CVE-2024-32498Medium· 6.5OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
OpenStack Cinder, Glance, and Nova vulnerable to arbitrary file access
▾ Sunlitcinder · cinderEPSS 0.83%via OSV
CVE-2022-47951Medium· 5.7OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
OpenStack Cinder, glance, and Nova vulnerable to Path Traversal
▾ Sunlitcinder · cinderEPSS 1.0%via OSV
CVE-2020-10755Medium· 6.5Openstack cinder Improper handling of ScaleIO backend credentials
Openstack cinder Improper handling of ScaleIO backend credentials
▾ Sunlitcinder · cinderEPSS 1.2%via OSV
CVE-2014-3641MediumOpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Cinder Exposure of Sensitive Information to an Unauthorized Actor vulnerability
▾ Sunlitcinder · cinderEPSS 1.9%via OSV
CVE-2015-1851MediumOpenStack Cinder file disclosure in image convert
OpenStack Cinder file disclosure in image convert
▾ Sunlitcinder · cinderEPSS 2.6%via OSV
CVE-2013-4202MediumOpenStack Cinder Denial of Service using XML entities
OpenStack Cinder Denial of Service using XML entities
▾ Sunlitcinder · cinderEPSS 2.6%via OSV
CVE-2015-5162High· 7.5OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
OpenStack Cinder, Glance, and Nova contain Uncontrolled Resource Consumption
▾ Twilightcinder · cinderEPSS 2.9%via OSV
CVE-2013-2255Medium· 5.9OpenStack Keystone and other components vulnerable to Improper Certificate Validation
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
▾ Sunlitpython-keystoneclient · python-keystoneclientEPSS 0.97%via OSV