Tagged “osv”
CVEs tagged osv, newest first.
5752 CVEsRSS
CVE-2015-3646MediumOpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
CVE-2014-3474LowOpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability
OpenStack Neutron Race Condition vulnerability
CVE-2016-4428Medium· 5.4OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
CVE-2017-1000426Medium· 6.1MapProxy vulnerable to cross-site scripting in demo service
MapProxy vulnerable to cross-site scripting in demo service
CVE-2018-16515High· 8.8Matrix Synapse Improper Signature Validation
Matrix Synapse Improper Signature Validation
CVE-2017-18191High· 7.5OpenStack Nova Denial of service attack on the compute host
OpenStack Nova Denial of service attack on the compute host
CVE-2016-4985High· 7.5OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
CVE-2018-12423High· 7.5Matrix Synapse Authorization Error
Matrix Synapse Authorization Error
CVE-2014-0204MediumOpenStack Identity Keystone Improper Privilege Management
OpenStack Identity Keystone Improper Privilege Management
CVE-2014-3473MediumHorizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
CVE-2014-3621MediumOpenStack Identity Keystone Exposure of Sensitive Information
OpenStack Identity Keystone Exposure of Sensitive Information
CVE-2017-9112Medium· 6.5OpenEXR invalid read
OpenEXR invalid read
CVE-2014-3594LowOpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
CVE-2017-12440High· 7.5Openstack Aodh can be used to launder Keystone trusts
Openstack Aodh can be used to launder Keystone trusts
CVE-2016-3691High· 8.8Kallithea Routes CSRF Bypass
Kallithea Routes CSRF Bypass
CVE-2013-2014MediumOpenStack Identity (Keystone) Denial of Service
OpenStack Identity (Keystone) Denial of Service
CVE-2017-7549Medium· 6.4instack-undercloud vulnerable to symlink attack on tmp files
instack-undercloud vulnerable to symlink attack on tmp files
CVE-2016-9605Medium· 6.1Cobbler Arbitrary File Read
Cobbler Arbitrary File Read
CVE-2017-3590Low· 3.3MySQL Connectors Privilege Escalation
MySQL Connectors Privilege Escalation
CVE-2014-3476MediumOpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
CVE-2021-25745High· 8.1Improper Input Validation in k8s.io/ingress-nginx
Improper Input Validation in k8s.io/ingress-nginx
CVE-2022-1592High· 8.2PoCServer-Side Request Forgery in scout-browser
Server-Side Request Forgery in scout-browser
CVE-2022-1053Critical· 9.1Tenant and Verifier might not use the same registrar data
Tenant and Verifier might not use the same registrar data
CVE-2013-2255Medium· 5.9OpenStack Keystone and other components vulnerable to Improper Certificate Validation
OpenStack Keystone and other components vulnerable to Improper Certificate Validation
CVE-2013-2228High· 8.1SaltStack RSA Key Generation allows remote users to decrypt communications
SaltStack RSA Key Generation allows remote users to decrypt communications
CVE-2013-0282MediumOpenStack Keystone allows context-dependent attackers to bypass access restrictions
OpenStack Keystone allows context-dependent attackers to bypass access restrictions
CVE-2013-0270Medium· 6.5OpenStack Keystone Denial of Service vulnerability via a large HTTP request
OpenStack Keystone Denial of Service vulnerability via a large HTTP request
CVE-2022-1554Medium· 6.8Path Traversal in scout-browser
Path Traversal in scout-browser
CVE-2022-25850High· 7.5ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)
ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)