Openstack
19 known vulnerabilities
Top Products
In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev
In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no P
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpo
OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS
OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron
OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not p
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditi
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin d
In OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can oc
In OpenStack Ironic before 35.0.2 (in a certain non-default configuration), instance_info['ks_template'] is rendered wit
An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes execu
An issue was discovered in OpenStack Keystone before 29.0.2. POST /v3/credentials did not validate that the caller-suppl
OpenStack Ironic before 35.0.1 allows ipmitool execution in a non-default configuration that has a console interface.
An issue was discovered in OpenStack Keystone 14 through 26 before 26.1.1, 27.0.0, 28.0.0, and 29.0.0. Restricted applic
OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 is affected by Server-Side Request Forgery (SSRF). By use
In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0, and 15.0.0, a user allowed to access the Vitrage
Frequently Asked Questions
How many CVEs affect Openstack?
Openstack has 19 CVE records in our database, including 1 critical and 3 high severity vulnerabilities.
What are the most severe Openstack vulnerabilities?
Openstack has 1 critical severity (CVSS 9.0+) and 3 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Openstack vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Openstack products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Openstack Vulnerabilities
CyberStrike scans your infrastructure for Openstack vulnerabilities and provides real-time remediation guidance.
Get Started