Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2025-65073

Medium priority

Some fixes available 8 of 21

OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.

3 affected packages

keystone, swift, heat

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keystone Fixed Fixed Ignored Ignored
swift Fixed Fixed Needs evaluation Needs evaluation
heat Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-7319

Medium priority
Vulnerable

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

1 affected package

heat

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heat Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-1625

Medium priority

Some fixes available 3 of 5

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the...

1 affected package

heat

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heat Not affected Fixed Fixed Fixed
Show less packages

CVE-2021-3585

Medium priority
Needs evaluation

A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.

1 affected package

tripleo-heat-templates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-heat-templates Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2021-4180

Medium priority
Needs evaluation

An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to...

1 affected package

tripleo-heat-templates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-heat-templates Needs evaluation
Show less packages

CVE-2018-10898

Low priority
Needs evaluation

A vulnerability was found in openstack-tripleo-heat-templates before version 8.0.2-40. When deployed using Director using default configuration, Opendaylight in RHOSP13 is configured with easily guessable default credentials.

1 affected package

tripleo-heat-templates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-heat-templates Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2017-2621

Medium priority
Ignored

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to...

1 affected package

heat

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heat
Show less packages

CVE-2017-12155

Medium priority
Needs evaluation

A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph...

1 affected package

tripleo-heat-templates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-heat-templates Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2017-15114

Medium priority
Needs evaluation

When libvirtd is configured by OSP director (tripleo-heat-templates) to use the TLS transport it defaults to the same certificate authority as all non-libvirtd services. As no additional authentication is configured this allows...

1 affected package

tripleo-heat-templates

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
tripleo-heat-templates Not in release Not in release Not in release Needs evaluation
Show less packages

CVE-2016-9185

Low priority
Ignored

In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.

1 affected package

heat

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
heat Not affected
Show less packages