Openstack Grizzly vulnerabilities
4 known vulnerabilities affecting openstack/grizzly.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2LOW2
Vulnerabilities
Page 1 of 1
CVE-2013-2030LOWCVSS 2.1v2013.12013-12-27
CVE-2013-2030 [LOW] CWE-264 CVE-2013-2030: keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure tem
keystone/middleware/auth_token.py in OpenStack Nova Folsom, Grizzly, and Havana uses an insecure temporary directory for storing signing certificates, which allows local users to spoof servers by pre-creating this directory, which is reused by Nova, as demonstrated using /tmp/keystone-signing-nova on Fedora.
nvd
CVE-2013-4261LOWCVSS 3.5≤ -2013-10-29
CVE-2013-4261 [LOW] CWE-119 CVE-2013-4261: OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, d
OpenStack Compute (Nova) Folsom, Grizzly, and earlier, when using Apache Qpid for the RPC backend, does not properly handle errors that occur during messaging, which allows remote attackers to cause a denial of service (connection pool consumption), as demonstrated using multiple requests that send long strings to an instance console and retrieving the c
nvd
CVE-2013-1838MEDIUMCVSS 4.0v2012.22013-03-22
CVE-2013-1838 [MEDIUM] CWE-399 CVE-2013-1838: OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.
nvd
CVE-2013-0335MEDIUMCVSS 6.0v2012.22013-03-22
CVE-2013-0335 [MEDIUM] CWE-264 CVE-2013-0335: OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated us
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
nvd