Tagged “pip”
CVEs tagged pip, newest first.
4668 CVEsRSS
CVE-2015-7546High· 7.5OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
OpenStack Identity Keystone and keystonemiddleware Insufficiently Protected Credentials
CVE-2017-12155Medium· 6.3Openstack tripleo-heat-templates unauthenticated file access
Openstack tripleo-heat-templates unauthenticated file access
CVE-2017-16239Medium· 6.5OpenStack Nova Filter Scheduler Bypass
OpenStack Nova Filter Scheduler Bypass
CVE-2017-17051High· 8.6OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
OpenStack Nova DoS by rebuilding the same instance with a new image multiple times
CVE-2016-6519Medium· 5.4Openstack Manila Persistent XSS in Metadata field
Openstack Manila Persistent XSS in Metadata field
CVE-2018-18482Medium· 6.5libpg_query memory leak
libpg_query memory leak
CVE-2018-12291High· 7.5Matrix Synapse Security Filtering Flaw
Matrix Synapse Security Filtering Flaw
CVE-2019-2435High· 8.1Improper Access Control in MySQL Connector Python
Improper Access Control in MySQL Connector Python
CVE-2017-9111High· 8.8OpenEXR invalid write
OpenEXR invalid write
CVE-2015-3646MediumOpenStack Keystone Logs Passwords
OpenStack Keystone Logs Passwords
CVE-2014-3474LowOpenStack Horizon Cross-site scripting (XSS) vulnerability
OpenStack Horizon Cross-site scripting (XSS) vulnerability
CVE-2017-7543Medium· 5.9OpenStack Neutron Race Condition vulnerability
OpenStack Neutron Race Condition vulnerability
CVE-2016-4428Medium· 5.4OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability
CVE-2017-1000426Medium· 6.1MapProxy vulnerable to cross-site scripting in demo service
MapProxy vulnerable to cross-site scripting in demo service
CVE-2018-16515High· 8.8Matrix Synapse Improper Signature Validation
Matrix Synapse Improper Signature Validation
CVE-2017-18191High· 7.5OpenStack Nova Denial of service attack on the compute host
OpenStack Nova Denial of service attack on the compute host
CVE-2016-4985High· 7.5OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
OpenStack Ironic Exposure of Sensitive Information to an Unauthorized Actor
CVE-2018-12423High· 7.5Matrix Synapse Authorization Error
Matrix Synapse Authorization Error
CVE-2014-0204MediumOpenStack Identity Keystone Improper Privilege Management
OpenStack Identity Keystone Improper Privilege Management
CVE-2014-3473MediumHorizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
CVE-2014-3621MediumOpenStack Identity Keystone Exposure of Sensitive Information
OpenStack Identity Keystone Exposure of Sensitive Information
CVE-2017-9112Medium· 6.5OpenEXR invalid read
OpenEXR invalid read
CVE-2014-3594LowOpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
OpenStack Dashboard (Horizon) Cross-site scripting (XSS) vulnerability in the Host Aggregates interface
CVE-2017-12440High· 7.5Openstack Aodh can be used to launder Keystone trusts
Openstack Aodh can be used to launder Keystone trusts
CVE-2016-3691High· 8.8Kallithea Routes CSRF Bypass
Kallithea Routes CSRF Bypass
CVE-2013-2014MediumOpenStack Identity (Keystone) Denial of Service
OpenStack Identity (Keystone) Denial of Service
CVE-2017-7549Medium· 6.4instack-undercloud vulnerable to symlink attack on tmp files
instack-undercloud vulnerable to symlink attack on tmp files
CVE-2016-9605Medium· 6.1Cobbler Arbitrary File Read
Cobbler Arbitrary File Read
CVE-2017-3590Low· 3.3MySQL Connectors Privilege Escalation
MySQL Connectors Privilege Escalation
CVE-2014-3476MediumOpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege