Search CVE reports


Toggle filters

31 – 33 of 33 results


CVE-2014-0056

Medium priority
Fixed

The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in...

1 affected package

neutron

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
neutron
Show less packages

CVE-2013-6491

Medium priority

Some fixes available 3 of 4

The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.

5 affected packages

cinder, keystone, neutron, nova, quantum

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
cinder
keystone
neutron
nova
quantum
Show less packages

CVE-2013-6419

Medium priority
Ignored

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the...

2 affected packages

neutron, nova

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
neutron
nova
Show less packages